![]() |
|
#126
|
||||
|
||||
|
I had some free time so I published on my personal blog and on my personal youtube channel a video of the exploit I've built with my own dll
http://www.youtube.com/watch?v=6304Q0YoiBg
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute Last edited by JRViejo : July 19th, 2010 at 12:19 PM. Reason: De-linked YouTube URL - JRViejo |
|
#127
|
||||
|
||||
|
Quote:
016169ebebf1cec2aad6c7f0d0ee9026 055a3421813caf77e1387ff77b2e2e28
__________________
Who controls the past controls the future Who controls the present controls the past vmworld Last edited by JRViejo : July 19th, 2010 at 12:33 PM. Reason: Removed Link from Quote - JRViejo |
|
#128
|
|||
|
|||
|
Preempting a Major Issue Due to the LNK Vulnerability - Raising Infocon to Yellow
http://isc.sans.edu/diary.html?storyid=9190 Quote:
Much easier, safer protection measures have already been discussed in this thread. ---- rich |
|
#129
|
|||
|
|||
|
Some tests here with the POC by our old *friend*
SSJ100:-http://ssj100.fullsubject.com/security-f7/vulnerability-in-windows-shell-could-allow-remote-code-execution-t187.htm#1302- and Ilya's reply to the DefenseWall test http://gladiator-antivirus.com/forum...owtopic=107368 Notice the result for the newly released Returnil System Safe 2011 RC Last edited by JRViejo : July 19th, 2010 at 04:43 PM. Reason: De-linked URL - JRViejo |
|
#130
|
|||
|
|||
|
UPDATE
http://isc.sans.edu/diary.html?storyid=9190 Quote:
|
|
#131
|
||||||
|
||||||
|
Quotes from Sans
Quote:
Explains maybe why the POC didn't work for me ? Quote:
The POC still didn't work from my desktop ? Quote:
Ahh, could be why ? Quote:
* Originally Posted by i_g Quote:
F-secure said this Quote:
So ? @EraserHW Sorry to say, even in HD mode i found it hard to view exactly what was happening Any chance you could give us a brief description ? TIA@Dark Star 72 Thanks for the links I didn't know ssj100 had branched out on his own Good news about Returnil System Safe 2011 RC @Rmus Thanks for the updates
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#132
|
||||
|
||||
|
Quote:
Just two things i wil mention: 1. Regarding CIS, it can be configured to intercept it. Post no. 125 of this thread. 2. PE gaurd seems to intercept it. Post no. 108 of this thread.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#133
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#134
|
||||
|
||||
|
Quote:
my personal blog is in italian and it's located here: https://www.pcalsicuro.com anyway I've written a similar blog post on Prevx blog at this address: http://www.prevx.com/blog/151/day-fl...t-Windows.html (this time in english) About the POC: I wouldn't share the sample outside the company at the moment, even though there's already a known PoC out there (personally I'd not have shared the PoC online, this allows attackers to better exploit the flaw. Anyway I saw someone else already did it). I'm sorry Anyway for any question, I'm here ![]() Actually, as I've written in the blog post, I think Microsoft will have some trouble in fixing this flaw, because it is not a bug - it's a feature used inside Windows internals.
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute Last edited by EraserHW : July 19th, 2010 at 09:40 PM. |
|
#135
|
||||
|
||||
|
Quote:
Sorry man I tried to do my best to record a good video ![]() Actually the video just shows how the exploit is working. I've written a PoC exploit from scratch and showed how a fake malicious DLL is loaded as soon as system starts rendering the icon
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#136
|
||||
|
||||
|
Quote:
|
|
#137
|
||||
|
||||
|
Right at the bottom of here - http://isc.sans.edu/diary.html?storyid=9181 - is this FIX
Quote:
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#138
|
||||
|
||||
|
@EraserHW
Thanks for your blog post link on this exploit POC Quote:
* Re video issue This is just an example of part of the fullscreen HD video as it appears on my comp. Looks blurry to me. See how it compares to your comp, could be just at my end ? * @Ronjor The plot thickens ! Quote:
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#139
|
|||
|
|||
|
|
|
#140
|
|||
|
|||
|
Hi MrBrian,
Do you have any idea what he's referring to in that Diary? (webDAV and how it relates to the exploit?) thanks, rich |
|
#141
|
||||
|
||||
|
@MrBrian Good find
@Rmus Re - WebDAV Appears to be these sorts of OS's that are vulnerable, business types and not domestic etc comps. Microsoft Windows 2000 Windows XP Professional Windows Server Quote:
Quote:
So i'm ok on XP/SP2 by the looks of things The .lnk POC didn't work anyway when i tested it, so ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#142
|
|||
|
|||
|
Quote:
Even two different systems with the same OS version, etc, can react differently to a real exploit. ---- rich |
|
#143
|
|||
|
|||
|
Quote:
From http://en.wikipedia.org/wiki/WebDAV: Quote:
From the Microsoft advisory Workarounds section: Quote:
Use of WebDAV is another means of infection and propagation for the .LNK vulnerability. |
|
#144
|
|||
|
|||
|
Quote:
---- rich |
|
#145
|
||||
|
||||
|
This might prove useful in .lnk analysis ?
Quote:
* Found this which "could" have some bearing on the latest situation ? Quote:
* Originally Posted by Rmus Quote:
Ain't that the truth ! And how frustrating for the bad guys, and girls ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#146
|
|||
|
|||
|
Quote:
Many Thanks for your upload at offensivecomputing ! |
|
#147
|
|||
|
|||
|
Quote:
Assuming I am correctly concluding that this exploit/feature allows code execution as explorer only, a better way to protect yourself from this exploit using CIS is to remove the default rule for explorer. As explorer is handling untrusted data (link shortcuts, possibly other exploitable aspects of files) it makes sense that manually restricting its actions would lend a security benefit. Doing so would not prevent the dll loading, but would prevent any actions taken by the malware through the compromised instance of explorer, and thus, prevent system compromise. However the compromised instance of explorer could, although it cannot make itself persistent on the system, attempt to escape the restriction of CIS using a shatter attack or keylog you. Unless you want to terminate and restart explorer after plugging in any flash drives but before entering any sensitive information, there are better solutions to this particular problem: AppLocker comes to mind. |
|
#148
|
|||
|
|||
|
|
|
#149
|
||||
|
||||
|
Not quite But could have been ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#150
|
||||
|
||||
|
Ronjor just posted this
http://www.microsoft.com/technet/sec...y/2286198.mspx So it looks like as im on XP/SP2 i'm not affected by this vulnerability/exploit No wonder it didn't work when i've tested it several times. Just goes to show, not updating to the latest patches etc SP3, "can" be a bonus Not recommending everyone does as i do though. In an earlier MS advisory, it mentioned mainly only business type OS's that were vulnerable. So something must have changed in the malware samples out there for this latest revision ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|