Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #101  
Old September 28th, 2011, 07:50 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,820
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Thanks as well. Can't believe I forgot to add it to the list.
__________________
  #102  
Old October 10th, 2011, 01:22 AM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Planned hotfix release is November 3 - see http://www.mountknowledge.nl/2011/01...ord-and-excel/.
  #103  
Old October 10th, 2011, 08:30 AM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Thanks for the update Mr. Brian.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #104  
Old October 10th, 2011, 10:06 AM
wat0114
 
Posts: n/a
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Good news, thanks MrBrian
  #105  
Old October 12th, 2011, 05:03 PM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,110
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Good news!
Just to clarify, that Hotfix will be included in Windows Update?
thanks

Edit
Just did the simple test described here: http://www.mountknowledge.nl/2011/01...ord-and-excel/

Althought the .exe is not allowed by SRP (not whitelisted in parental controls), it was able to run!
__________________
Linux Mint 13 MATE x64

Last edited by AlexC : October 12th, 2011 at 05:27 PM.
  #106  
Old October 12th, 2011, 06:03 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,441
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

It makes us want to slap whoever thought of that "design", right? I wonder if whoever came with that idea was eating some magic mushrooms.
  #107  
Old October 12th, 2011, 06:16 PM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,110
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Lol! Thats right!

This time i repeated the process with a .exe that requires admin. privileges and it was unable to run. I got the message:
"CreateProcessAsUser failed: 740"
__________________
Linux Mint 13 MATE x64
  #108  
Old November 2nd, 2011, 10:50 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,441
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

One more day, folks! Just on more day!!!

-edit-

I suppose I was wrong... It's past half day of 04-11-2011, and still nothing. I wonder if it's still day 3 in US?

I wonder if this is going to happen at all, or if they just prefer to let the "backdoor" be? lol

Last edited by m00nbl00d : November 4th, 2011 at 10:01 AM.
  #109  
Old November 4th, 2011, 08:58 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,441
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Is this damn thing for real or simply a joke? Are you familiar with any official information from Microsoft stating they're going to fix it?

It's already day 5, and I'm sure the U.S is only like eight hours behind, so... is this actually for real or was it simply some stupid joke?
  #110  
Old November 5th, 2011, 08:10 PM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,110
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

I'm also waiting...
__________________
Linux Mint 13 MATE x64
  #111  
Old November 9th, 2011, 08:23 AM
RichieB2B RichieB2B is offline
Infrequent Poster
 
Join Date: Jan 2011
Posts: 13
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

It seems KB370118 was just an internal fix number. It has just been released as KB2532445 at http://support.microsoft.com/kb/2532445. The hotfix is available upon request (see link at top of the article).

This fix almost got delayed again, because of a conflict with another hotfix to the kernel. Luckily KB2532445 drew the shortest straw and was released first.
  #112  
Old November 9th, 2011, 04:49 PM
Zorak's Avatar
Zorak Zorak is offline
Regular Poster
 
Join Date: Jan 2010
Location: Australian Capital Territory
Posts: 139
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Thanks RichieB2B

Will give the hotfix a go once I've bedded down the latest round of Windows Updates.

Cheers.
__________________
Win7 Pro x64 SP1 - SUA - UAC(max) - SRP - EMET 3.5 Realtime: Webroot SecureAnywhere - Windows Firewall On Demand: Hitman Pro - Emsisoft Emergency Kit - OTL - Secunia PSI Imaging: Windows Backup & Restore - Macrium Reflect Free Router: Linksys
  #113  
Old November 9th, 2011, 09:48 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,441
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Thanks...

Did any systems blow up already after applying the hotfix?
  #114  
Old November 9th, 2011, 11:06 PM
wat0114
 
Posts: n/a
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by m00nbl00d
Did any systems blow up already after applying the hotfix?

Come on m00nbl00d, I'd have thought you'd be on this like bees to honey, you were so impatiently waiting for it
  #115  
Old November 9th, 2011, 11:12 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,441
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by wat0114
Come on m00nbl00d, I'd have thought you'd be on this like bees to honey, you were so impatiently waiting for it



I won't be checking my e-mail any time soon. I'm lazy to switch user accounts, right now. I'm on my restricted user account to access the web, in general. I have another user account for accessing my e-mail.

So, did you blow up you computer?
  #116  
Old November 9th, 2011, 11:16 PM
wat0114
 
Posts: n/a
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by m00nbl00d
So, did you blow up you computer?

Too chicken to try it on the host machine yet Will try the vm first and let you know tomorrow after I run it for a while.
  #117  
Old November 10th, 2011, 07:12 PM
wat0114
 
Posts: n/a
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by wat0114
Too chicken to try it on the host machine yet Will try the vm first and let you know tomorrow after I run it for a while.

installed on the vm last night, no issues earlier today, so I installed on the host and all is fine so far, althtough no guarantees something won't eventually surface. You might want to image your system before applying the patch if that's what you're into
  #118  
Old November 11th, 2011, 03:12 AM
Zorak's Avatar
Zorak Zorak is offline
Regular Poster
 
Join Date: Jan 2010
Location: Australian Capital Territory
Posts: 139
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Thanks wat0114 for being the crash test dummy
__________________
Win7 Pro x64 SP1 - SUA - UAC(max) - SRP - EMET 3.5 Realtime: Webroot SecureAnywhere - Windows Firewall On Demand: Hitman Pro - Emsisoft Emergency Kit - OTL - Secunia PSI Imaging: Windows Backup & Restore - Macrium Reflect Free Router: Linksys
  #119  
Old November 11th, 2011, 08:41 AM
wat0114
 
Posts: n/a
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

LOL! you're welcome
  #120  
Old November 11th, 2011, 12:35 PM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Just looked at this thread again lol. About time Microsoft released it. Time to install. Good to hear you didn't have any issues wat.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #121  
Old November 11th, 2011, 12:58 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,441
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by 1chaoticadult
Just looked at this thread again lol. About time Microsoft released it. Time to install. Good to hear you didn't have any issues wat.

So, you're going to be the second lab rat... We need a third one...
  #122  
Old November 11th, 2011, 01:43 PM
wat0114
 
Posts: n/a
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by m00nbl00d
So, you're going to be the second lab rat...



Quote:
We need a third one...

Why thank you, m00nbl00d!

Quote:
Originally Posted by 1chaoticadult
Good to hear you didn't have any issues wat.

Still waiting with trepidation, but so far so good
  #123  
Old November 11th, 2011, 03:43 PM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Quote:
Originally Posted by m00nbl00d
So, you're going to be the second lab rat... We need a third one...

Yep So far the hotfix is working without issues.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #124  
Old November 13th, 2011, 08:24 AM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,110
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Working fine here either.
__________________
Linux Mint 13 MATE x64
  #125  
Old January 3rd, 2012, 06:53 PM
Joeythedude's Avatar
Joeythedude Joeythedude is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 519
Default Re: Circumventing SRP and AppLocker by design, with LoadLibraryEx

Does anyone know if this has been released through Windows Update ?
__________________
The Wilders Paradox : "If you visit wilders , you don't need to"

My Setup

I recommend this as a "must read" thread
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:53 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums