New .lnk type vulnerability

Discussion in 'other security issues & news' started by CloneRanger, Aug 19, 2010.

Thread Status:
Not open for further replies.
  1. RHE10

    RHE10 Registered Member

    Joined:
    Aug 8, 2010
    Posts:
    24
    Thanks and I see. Not sure why the earlier decision to not post youtube av-testing videos is related and applicable to giving a link to a page demonstrating a vulnerability being talked about in the thread, but OK. At least people can copy and paste I guess. Cheers.
     
  2. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    From Windows DLL load hijacking exploits go wild:
     
  3. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,001
    Location:
    U.S.A.
    RHE10, all sorts of video pages have been de-linked, and besides the fact that everyone wants to be a publisher these days, another reason, as stated in those policies, is to prevent click-thru boosts, driving traffic from Wilders to these sites to up video counts. And yes, by still allowing the de-linked URL, visitors can copy & paste those URLs into their browsers, as not to miss any info.
     
  4. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    From Binary Planting Update, Day 7:
     
  5. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Never heard of Program Manager Group Converter in the link MrBrian gave :thumb:

    Did a search on my comp and it didn't find it ? Don't have WebDav either.
     
  6. PunchsucKr

    PunchsucKr Registered Member

    Joined:
    Jul 29, 2009
    Posts:
    138
    hmmm...we've got another one!! so any idea whether LUA+Applocker would prevent this attack??

    I am in half mind to shift to Ubuntu now.. but just hanging on to 7 because of the $$ i paid to have it.
     
  7. trismegistos

    trismegistos Registered Member

    Joined:
    Jan 29, 2009
    Posts:
    363
    From Slimming Down Windows Xp: The Complete Guide, Bold_Fortune's Complete Guide To Slimming Down Windows XP

    For Program Manager Group Converter
    For WebDav:
    By now, you might already have disabled Webclient service since you probably don't need WEBDAV.

    You can delete PROGMAN.EXE. I use XPLITE, to temporarily disable windows file protection. See the above link on how to do it safely. But first, do a system image backups(that you have validated that can restore successfully).

    Unfortunately as quoted GRPCONV.EXE is needed for some programs to install. Don't delete!!! You can probably block GRPCONV.EXE from executing.

    EDIT:
    But then again, the most practical solution would be is to block or prompt for unknown or untrusted dlls and executables from untrusted folders by the use of SRP/AE/HIPS/Applocker or containment by opening files throught a sandboxed explorer/usb drives.

    To emphasize:
     
    Last edited: Aug 25, 2010
  8. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    From Better, Faster, Stronger: DLLHijackAuditKit v2:
     
  9. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,001
    Location:
    U.S.A.
     
  10. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    I've verified that the proof-of-concept for VLC Media Player works. Also, Comodo Internet Security, when used as an anti-executable with the DLL interception option, blocks the DLL. The message box below appears if and only if the DLL is loaded.

    I would expect SRP/AppLocker to also be effective when they're configured to block DLLs.
     

    Attached Files:

    Last edited: Aug 25, 2010
  11. wat0114

    wat0114 Guest

    Does it not seem avoiding stupidness /sic will also prevent these exploits?
     
  12. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    @ trismegistos

    Hi, thanks for taking the time to put that together :thumb:

    Went and rechecked and i do have a few of those, and PG blocks them :)

    pm.gif

    grp.gif

    Initially i searched for Program Manager Group Converter duh :D

    You're right :thumb: i have disabled Webclient service ;)

    wc.gif

    I have looked at - http://www.graphixanstuff.com - before, but some ago, so had forgotten about it. Very indepth info, thanks for the reminder :thumb:

    *

    @ MrBrian

    If you ran the DLLHijackAuditKit you get a medal from me ;) Good to know CIS blocks the .DLL, i expect ProcessGuard would too.

    @ JRViejo

    Re - Hackers post attacks for 40-plus apps.

    That didn't take long :eek: only another few hundred to go :D
     
  13. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,001
    Location:
    U.S.A.
    CloneRanger, at the rate they are going, hacking all the 200+ programs should be done by Friday. :ouch: ;)
     
  14. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    I didn't try DLLHijackAuditKit actually, so no medal ;).

    For the record, CIS blocks these vulnerabilities only when the Image Execution Control Level is set to Aggressive and the appropriate extensions are specified in Files to Check. These are not the default settings.
     
  15. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    :D

    @ MrBrian

    About CIS = OK

    If not the DLLHijackAuditKit what you you run/test with then ?
     
  16. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    I used the POC for VLC Media Player at the biggest exploits site.
     
  17. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
  18. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    .

    I think i know which one you mean ;)
     
  19. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,074
    Location:
    Texas
  20. tgell

    tgell Registered Member

    Joined:
    Nov 12, 2004
    Posts:
    1,097
    Also noticed that Avast! is included. :(

    edit: to be fixed in the next build.
     
    Last edited: Aug 26, 2010
  21. RHE10

    RHE10 Registered Member

    Joined:
    Aug 8, 2010
    Posts:
    24
    Hmm, and I thought only TCP traffic needed to be blocked for ports 139/445, but looks like it's UDP as well...

    http://www.kb.cert.org/vuls/id/707943

     
  22. wearetheborg

    wearetheborg Registered Member

    Joined:
    Nov 14, 2009
    Posts:
    667
    What is SMB?
     
  23. RHE10

    RHE10 Registered Member

    Joined:
    Aug 8, 2010
    Posts:
    24
    Server Message Block, a networking protocol, used to share resources between parts of a network.
     
  24. Boyfriend

    Boyfriend Registered Member

    Joined:
    Jun 7, 2010
    Posts:
    1,070
    Location:
    Pakistan
  25. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It,s a pity that you can no longer do this with latest CIS v 5 RC. They removed dll control from Defence Plus. What a pitty!!

    I posted a thread but seems developers will not take any notice.

    http://forums.comodo.com/beta-corner-cis/how-cis-hips-is-going-to-protect-against-this-t60858.0.html
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.