![]() |
|
#76
|
||||
|
||||
|
Quote:
Quote:
Quote:
Note, however: Quote:
---- rich Last edited by Rmus : November 14th, 2011 at 04:34 PM. |
|
#77
|
|||
|
|||
|
I contacted Faronics and sent them the Symantec and Securelist analyses of the Duqu exploit. They responded saying that based on that information, their product, Anti-Executable, will block the exploit with DLL protection enabled.
---- rich Last edited by Rmus : November 14th, 2011 at 03:21 PM. |
|
#78
|
||||
|
||||
|
Tested both my XP/SP2 with NO updates
on FF & IE with hawki's link from post # 75 Not sure why with FF it was HTTPS & with IE it was only HTTP ? Anyway ... FF = IE6 not allowing Fonts = Same as FF = ![]() IE6 allowing Fonts =
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#79
|
||||
|
||||
|
Kaspersky Lab protects against duqu-originated zero-day vulnerability in windows
Published November 13th, 2011 - 09:01 GMT Press Release Kaspersky Lab, a leading developer of secure content and threat management solutions, announces that its security solutions are now detecting the vulnerability that was used for distributing all known versions of the infamous Duqu Trojan. Kaspersky Lab’s experts have successfully implemented protection against Trojan.Win32.Duqu.a as well as other malicious programs exploiting the CVE-2011-3402 vulnerability. http://www.albawaba.com/business/pr/...windows-400709 |
|
#80
|
||||
|
||||
|
Quote:
Quote:
The reason for some doubts was because I remember a few months ago, katio said that a kernel exploit such as the one involving this embedded true type font vulnerability would bypass any AE-like protection/HIPS/LUA/Applocker/Sandboxie. i.e, if this single exploit has both the privilege escalation and remote code execution. Tzuk mentioned or rather implied also that before about the possibility of an EOT vulnerability kernel exploit or any kernel exploit with remote code execution breaking out of Sandboxie... http://www.sandboxie.com/phpbb/viewtopic.php?p=43628 and http://www.sandboxie.com/phpbb/viewtopic.php?p=53719 Such exploit should be rare but I guess not anymore. ------------ To harden Sandboxie, users can do this as presented by Nicks... http://www.sandboxie.com/phpbb/viewt...r=asc&start=15
__________________
-http://www.veteranstoday.com/author/henderson/ -http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/ Last edited by trismegistos : November 17th, 2011 at 10:41 AM. |
|
#81
|
|||
|
|||
|
|
|
#82
|
|||
|
|||
|
Quote:
Is it not clear that the United States and Israel are responsible for Stuxnet? |
|
#83
|
||||
|
||||
|
Quote:
So, my understanding of a kernel exploit of the embedded true type font vulnerability is that it can bypass SRP/Applocker/AE/HIPS/Sandboxie as the kernel exploit tries to load the driver on kernel mode. Hoping, I'm wrong. Only testing with the actual kernel exploit will be able to confirm such speculation. Still, there's a greater urgency or a greater need for a patch or at least people should at least apply the workaround on the buggy T2embed.dll file (Fix It program from Microsoft).
__________________
-http://www.veteranstoday.com/author/henderson/ -http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/ Last edited by trismegistos : November 17th, 2011 at 10:43 AM. |
|
#84
|
||||
|
||||
|
Next "son"?
![]() Quote:
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#85
|
||||
|
||||
|
After reading Ichito's post I wanted to see what the MalCon conference was about and who would be presenting about Stuxnet 3.0. When I went to Malcon I saw this:
Quote:
Strange coincidence? Realizing the mistake I found the right site : http://malcon.org
__________________
Americans are the enemy? Mil. can arrest you? What the heck is going on? |
|
#86
|
||||
|
||||
|
__________________
-http://www.veteranstoday.com/author/henderson/ -http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/ Last edited by trismegistos : November 29th, 2011 at 08:34 PM. |
|
#87
|
|||
|
|||
|
|
|
#88
|
||||
|
||||
|
So it looks like, the dropper of Duqu can bypass all security protections(almost).
Exploit -> kernel -> driver in kernel -> loader dll in services.exe -> big pnf in services.exe -> big pnf installing from lsass or AV process. [ from http://www.securelist.com/en/blog/20...and_TVs_Dexter ] The exploit is on the "Vulnerability in TrueType font parsing" which could allow elevation of privileges and arbitrary code execution. In this case, the shellcode executed goes into the kernelmode, win32k.sys, gaining Ring Zero or kernel or the highest privileges bypassing most security, AVs, LUA-SRP, Applocker, probably AE and possibly even Sandboxie and some classical HIPS, once the recipient/victim of a corporation targetted for e.g. opens a seemingly benign Microsoft document file. This is what is HD Moore is warning, a kernel exploit that doesn't require an initial remote or local arbitrary code execution unlike the usual local kernel exploits(EoP) requiring an initial exploit of those types to gain local access. Mostly, local kernel exploits would be pushed by a dropper executable(obfuscated exe's or dlls) to elevate privileges. Most AVs, and such protections like SRP, Applocker, AE would easily detect those payloads. I am not sure how most classical HIPS would fare in this case of stopping the loading of the malicious driver depending on how deep down to the kernel it guards. This is one rare case, AE would probably not block as the payload is not an ordinary executable but a kernel driver in kernel space and the initial dropper is the exploit's shellcode itself before loading the main dropper, the malicious dll. SRP even with the grainier dll control would fail to catch the malicious dll, main dropper. Sandboxie can be bypassed by these types of kernel exploits as implied by tzuk's statements... http://www.sandboxie.com/phpbb/viewtopic.php?p=53719 Not sure how EMET, ASLR, DEP, Sehop, et al will be successful in preventing the exploit of this malwae. Only with the actual malware testing with the actual document file containing the kernel exploit, the kernel driver and the malicious dll can we say for certain. Fortunately for us, this is easy to mitigate by installing the MS' Fix It program for the meanwhile to block the access to t2embedd.dll as we wait for the patch. T2embedd.dll was the same buggy dll which had been patched before (as in the past EOT vulnerability). I preferred unregistering it permanently which might, however, block some functionalities in certain programs. Some functionalities, which for now I don't really need and have better alternatives.
__________________
-http://www.veteranstoday.com/author/henderson/ -http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/ |
|
#89
|
||||
|
||||
|
Q - Would Applocker and Anti-Executable Type Products stop it at the Loader DLL main dropper ?
I know the kernel is still exploited but if the DLL is stopped from loading then the rest of this version of the exploit would be stopped. @trig why wouldn't SRP catch the Loader DLL main dropper ?
__________________
The Wilders Paradox : "If you visit wilders , you don't need to" ![]() My Setup I recommend this as a "must read" thread |
|
#90
|
|||
|
|||
|
Quote:
---- rich |
|
#91
|
||||
|
||||
|
"Stuxnet/Duqu: The Evolution of Drivers" : http://www.securelist.com/en/analysi...ion_of_Drivers
Quote:
"Stuxnet weapon has at least 4 cousins: researchers" : http://www.reuters.com/article/2011/...7BR1EV20111228 Quote:
__________________
A man's pride shall bring him low: but honour shall uphold the humble in spirit: Proverbs 29,23. "Only the wasteful virtues earn the sun": William Butler Yeats, April 27, 1916. |
|
#92
|
||||
|
||||
|
Quote:
The only way to find out is to have Faronics ask a Duqu sample from Kaspersky experts and test that. If the dll is loaded/dropped in userspace, SRP will stop that but this is not the case for Duqu.
__________________
-http://www.veteranstoday.com/author/henderson/ -http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/ |
|
#93
|
||||
|
||||
|
Quote:
https://www.securelist.com/en/blog/6...Duqu_Framework
__________________
A man's pride shall bring him low: but honour shall uphold the humble in spirit: Proverbs 29,23. "Only the wasteful virtues earn the sun": William Butler Yeats, April 27, 1916. |
|
#94
|
||||
|
||||
|
Quote:
__________________
A man's pride shall bring him low: but honour shall uphold the humble in spirit: Proverbs 29,23. "Only the wasteful virtues earn the sun": William Butler Yeats, April 27, 1916. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|