[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Internet Explorer. Tampilkan semua postingan
Tampilkan postingan dengan label Internet Explorer. Tampilkan semua postingan

14/10/11

Oscommerce Malware Infection + Internet Explorer Exploit [video]

 

Description: OsCommerce suffers of few vulnerabilities that can lead an attacker to upload files and execute remote code. What i want to show you is how probably an attacker has infected a site running an old copy of osCommerce to spread malware.
Read More...

13/10/11

Patch Internet Explorer Now

Yesterday was Microsoft's Patch Tuesday for the month of October. There were a total of eight new security bulletins--not too many, but enough to keep IT admins busy for a while. While most of the vulnerabilities addressed are not imminent threats, security experts are virtually unanimous that patching Internet Explorer should be priority one.

First, let's take a brief look at the security bulletins Microsoft released for Patch Tuesday:

Internet ExplorerSecurity experts agree that patching Internet Explorer is a priority.MS11-075 (Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution): Could be exploited to run malicious code from a rogue DLL file. MS11-076 (Vulnerability in Windows Media Center Could Allow Remote Code Execution): Addresses a publicly disclosed vulnerability in Windows Media Center that could be used to run malicious code from a rogue DLL file.

MS11-077 (Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution): Fixes four different vulnerabilities in Microsoft Windows, including one that could allow an attacker to execute malicious code by luring someone to open a malicious font file.

MS11-078 (Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution): Fixes a critical vulnerability in .NET Framework and Microsoft Silverlight that can be exploited to run malicious code when someone visits a compromised website.

MS11-079 (Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution): Resolves five vulnerabilities in Microsoft Forefront Unified Access Gateway, one of which could enable an attacker to execute malicious code by luring the user to visit a compromised website.

MS11-080 (Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege): Deals with a possible elevation of privileges vulnerability, but an attacker would have to log on locally to the system using valid credentials, so this presents very little risk.

MS11-081 (Cumulative Security Update for Internet Explorer): This month's Cumulative Security Update for Internet Explorer addresses eight vulnerabilities, including one which can be used to execute malicious code simply by luring a user to visit a compromised website.

MS11-082 (Vulnerabilities in Host Integration Server Could Allow Denial of Service): Deals with two vulnerabilities in Host Integration Server that could be used for a denial of service attack.

To average users and many IT admins, the descriptions all sound somewhat ominous, and--to be fair--they are all updates that should be applied if you use the affected products or services. But, only two of the security bulletins (MS11-078 and MS11-081) are rated as Critical by Microsoft, and only one of them is being pushed as a top priority by security experts.

Joshua Talbot, security intelligence manager, Symantec Security Response, says, "Internet Explorer vulnerabilities are very common targets of attackers and it will probably be no different with these. Users and IT departments should patch these right away."

Paul Henry, security and forensic analyst at Lumension, stresses about MS11-081, "None of the patched issues are related to active exploits; however users are urged to patch this as a high priority."

Andrew Storms, director of security operations at nCircle, implores, "Patching Internet Explorer should be at the top of everyone's list."

Amol Sarwate, Manager of Vulnerability Labs for Qualys, agrees, "The highest priority should be given to MS11-081 which patches a code execution vulnerability in Internet Explorer."

VMWare's Jason Miller, and Marcus Carey from Rapid7 also cite updating Internet Explorer as the number one priority from this Patch Tuesday. I think it is safe to say that we have a general consensus on which update is the most urgent.

Make sure you apply all updates that affect your systems as soon as possible. But, if you have testing and patch rollout processes to deal with, make sure you address MS11-081 first.
Read More...

12/10/11

Internet Explorer 9 haunted by 'critical' security vulnerabilities

Summary: Microsoft fixes drive-by download flaws in the latest version of its dominant Internet Explorer browser and warns that exploits could emerge within 30 days.

Microsoft’s shiny new Internet Explorer 9 browser contains critical security vulnerabilities that expose users to drive-by download attacks, the company warned today.

The IE warning highlights this month’s batch of security patches from Microsoft where the company shipped eight security bulletins (two critical, six important) to cover gaping holes in Internet Explorer, .NET Framework & Silverlight, Microsoft Windows, Microsoft Forefront UAG and Microsoft Host Integration Server.follow Ryan Naraine on twitter

According to Microsoft, the IE vulnerabilities could be exploited if a user simply surfs to a maliciously rigged website.

The IE update (MS11-081), available for all users or Microsoft Windows and all versions of Internet Explorer, covers at least eight documented security holes in the world’s most widely used browser. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

The update fixes the vulnerabilities by modifying the way that Internet Explorer handles objects in memory and the way that Internet Explorer allocates and accesses memory, Microsoft explained.

Microsoft is urging all Windows users to treat this with the utmost priority because of the likelihood of reliable exploit code within 30 days. Malicious hackers typically reverse-engineer the patches to identify the flaws and write exploits immediately to launch malware attacks.

The second “critical” update (MS11-078) addresses a vulnerability in .NET Framework and Microsoft Silverlight that could expose users to remote code execution attacks.

The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.

Microsoft warns that a victim could be exploited if he/she browses to a malicious webpage with aSilverlight-enabled browser.

As with the IE patch, Microsoft exploits to see “reliable exploits” for Silverlight 3 over the next 30 days.

The company also raised an alert for a third bulletin (MS11-077) that covers at least four documented vulnerabilities in Windows kernel-mode drivers (Win32k.sys).

The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment, the company explained.

The security update addresses the vulnerabilities by correcting the way that the Windows kernel-mode drivers validate input passed from user mode, handle the TrueType font type, allocate the proper buffer size before writing to memory, and manage kernel-mode driver objects.

This month’s Patch Tuesday batch also covers five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL.

It also provides fixes for a solitary flaw in the Microsoft Windows Ancillary Function Driver (AFD) and two publicly disclosed vulnerabilities in Host Integration Server.

The Host Integration Server vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478.
Read More...

06/10/11

NSS Labs offers reward money for fresh exploits

The company has set aside $4,400 for rewards for working exploits for 12 vulnerabilities

NSS Labs is sweetening the pot for its ExploitHub marketplace by offering rewards to security gurus who can write working exploits for a dozen "high-value" vulnerabilities.

The company, which has set aside $4,400 in reward money, plans to give $100 to $500 to the first people to submit a working exploit for the vulnerabilities. Ten of the vulnerabilities concern Microsoft's Internet Explorer browser, and two were found in Adobe's Flash multimedia program.

[ The Web browser is your portal to the world -- as well as the conduit that lets in many security threats. InfoWorld's expert contributors show you how to secure your Web browsers in this "Web Browser Security Deep Dive" PDF guide. ]

The exploits must be client-side remote exploits that can result in code execution. Proof-of-concept code and denial-of-service conditions do not qualify. NSS Labs will pay the developer with American Express gift cards. Residents from countries that the U.S. has a standing embargo against are not allowed to participate.

NSS Labs said that those who win can then sell their exploits on ExploitHub, a marketplace the company set up for penetration testers to acquire exploits to test against their infrastructure. ExploitHub was set up to help with the development of penetration testing tools and to assist computer security researchers.

Those who write the winning exploits may then sell their code on ExploitHub, with NSS Labs taking a 30 percent commission. Penetration testers can also make requests via the marketplace for exploits for specific vulnerabilities. Those who want to buy exploits are vetted by NSS Labs to ensure the marketplace is not abused.

ExploitHub also only sells exploits for vulnerabilities that have been patched and does not host ones for zero-day vulnerabilities. The vulnerabilities that NSS Labs is offering the reward for are:
  1. CVE-2011-1256: Microsoft Internet Explorer CElement Memory Corruption
  2. CVE-2011-1266: Microsoft Internet Explorer VML vgx.dll Use After Free
  3. CVE-2011-1261: Microsoft Internet Explorer selection.empty Use After Free
  4. CVE-2011-1262: Microsoft Internet Explorer Redirect Memory Corruption
  5. CVE-2011-1963: Microsoft Internet Explorer XSLT Memory Corruption
  6. CVE-2011-1964: Microsoft Internet Explorer Style Object Memory Corruption
  7. CVE-2011-0094: Microsoft Internet Explorer CSS Use After Free Memory Corruption
  8. CVE-2011-0038: Microsoft Internet Explorer 8 IESHIMS.DLL Insecure Library Loading
  9. CVE-2011-0035: Microsoft Internet Explorer Deleted Data Source Object Memory Corruption
  10. CVE-2010-3346: Microsoft Internet Explorer HTML Time Element Memory Corruption
  11. CVE-2011-2110: Adobe Flash Player ActionScript Function Variable Arguments Information
  12. CVE-2011-0628: Adobe Flash Player Remote Integer Overflow Code Execution
Read More...

23/09/11

Fixes in the Works For SSL Attack, But Support Lacking for Newer Versions of Protocol

SSLWith the release of the BEAST SSL attack research due tomorrow, researchers are beginning to take note of potential fixes and mitigations for the attack. One of the possibilities is moving to newer versions of TLS that are not vulnerable to the attack, but the problem is that there is precious little adoption of those newer versions.

Some of the browser vendors have been looking at possible remedies for the attack on TLS developed by Juliano Rizzo and Thai Duong, and Opera was the first to develop a fix for it. The company initially implemented the fix in its browser, but then discovered that it broke a small percentage of sites and did not push the fix into the final version of Opera. The default configuration of Opera isn't vulnerable to the new attack, but if users change some settings, the browser can become susceptible to the attack.

Rizzo and Duong's attack, which Rizzo will present at the Ekoparty conference on Friday, is aimed at TLS 1.0, which is an older version of the protocol, and the newer versions are not vulnerable. However, as Opera's own research found, the adoption of TLS 1.1 and 1.2 among Web sites is far too low to just make the switch in the browser. Opera found that just 0.25 percent of sites supports TLS 1.1 and 0.02 percent support version 1.2. TLS 1.0 is quite an old standard, and even versions 1.1 and 1.2 have been approved for several years now, but many of the more recent versions of the major browsers don't support the newer releases of TLS, which presents a problem for site operators who would like to upgrade. If their users can't handle TLS 1.1 or 1.2, upgrading could cost them customers.

For example, the latest version of Mozilla Firefox has the boxes for SSL 3.0 and TLS 1.0 checked by default and there is no option for users to enable support for newer versions of TLS. Internet Explorer 9 gives users the ability to enable support for TLS 1.1 and 1.2 in Internet Options under the Advanced tab. But, unless the site on the other end of the connection is using a newer version of the protocol as well, that doesn't do the user much good.

Opera isn't the only vendor who is working on a fix. Google also has been preparing a patch for its Chrome browser and the company has pushed that fix to its development channel already, officials say. The company is hoping to have the fix go through the typical process of moving to the beta channel and then the stable channel without having to push it out as an emergency fix.

A new report by security researcher Thierry Zoller that looked at browser support for various versions of the TLS protocol found that support for anything newer than TLS 1.0 is quite spotty. Also in the report, Zoller recommends that sites that use SSL drop support for SSL 2.0 and 3.0 and only support TLS 1.0 and later.

nb : threatpost Read More...

16/09/11

Microsoft patches 15 important vulnerabilities

This month, Microsoft issued 5 security bulletins covering 15 vulnerabilities in Excel and Windows. These updates are considered important rather than critical, as by the time of the patch there was no malicious code exploiting the vulnerabilities in the wild. Adobe also released a security bulletin patching 13 vulnerabilities in Acrobat Reader. Websense® Security Labs highly recommends applying the updates in order to avoid cyber criminals who may use these security holes for their malicious activities.

Arguably the most important bulletin is MS11-072, which targets five different vulnerabilities in Microsoft Office. An attacker could use any of these to execute arbitrary code on the computer with the same access rights as the user. This is a focus for any security researcher as hackers are constantly looking for newer ways to distribute their badware. Such issues are probably getting more and more headlines as Adobe's sandboxing system and regular security patches seem to be paying off, meaning an up-to-date system is much less prone to successful exploits by vulnerabilities in PDFs.

This does not mean, of course, that we will see no more vulnerabilities in Acrobat Reader. This Tuesday Adobe Issued a security bulletin too, fixing 13 vulnerability issues in their product. Each of the vulnerabilities could allow an attacker to execute a code on the host computer allowing them to take full control of it. This patch is rated as critical, therefore it is strongly recommended to apply it.



Also worth mentioning is that many companies have updated their DigiNotar certificates - Microsoft, Adobe, and even Mozilla Firefox issued the updates. Firefox even released an additional security patch targeting this issue. Please check that you have applied the latest updates so you are fully protected.

Is your organization using the latest Firefox 6 or Internet Explorer 9? Which one did you find more secure? Give us your thoughts in the comments.

Vulnerabilities patched by Microsoft on 13 September 2011:
MS11-070 WINS Local Elevation of Privilege Vulnerability (CVE-2011-1984)
MS11-071 Windows Components Insecure Library Loading Vulnerability (CVE-2011-1991)
MS11-072 Excel Use after Free WriteAV Vulnerability (CVE-2011-1986)
MS11-072 Excel Out of Bounds Array Indexing Vulnerability (CVE-2011-1987)
MS11-072 Excel Heap Corruption Vulnerability (CVE-2011-1988)
MS11-072 Excel Conditional Expression Parsing Vulnerability (CVE-2011-1989)
MS11-072 Excel Out of Bounds Array Indexing Vulnerability (CVE-2011-1990)
MS11-073 Office Component Insecure Library Loading Vulnerability (CVE-2011-1980)
MS11-073 Office Uninitialized Object Pointer Vulnerability (CVE-2011-1982)
MS11-074 XSS in SharePoint Calendar Vulnerability (CVE-2011-0653)
MS11-074 HTML Sanitization Vulnerability (CVE-2011-1252)
MS11-074 Editform Script Injection Vulnerability (CVE-2011-1890)
MS11-074 Contact Details Reflected XSS Vulnerability (CVE-2011-1891)
MS11-074 SharePoint Remote File Disclosure Vulnerability (CVE-2011-1892)
MS11-074 SharePoint XSS Vulnerability (CVE-2011-1893)

Vulnerabilities patched by Adobe on 13 September 2011:
Local privilege-escalation vulnerability (Adobe Reader X (10.x) on Windows only) (CVE-2011-1353).
Security bypass vulnerability that could lead to code execution (CVE-2011-2431).
Buffer overflow vulnerability in the U3D TIFF Resource that could lead to code execution (CVE-2011-2432).
Heap overflow vulnerability that could lead to code execution (CVE-2011-2433).
Heap overflow vulnerability that could lead to code execution (CVE-2011-2434).
Buffer overflow vulnerability that could lead to code execution (CVE-2011-2435).
Heap overflow vulnerability in the Adobe image parsing library that could lead to code execution (CVE-2011-2436).
Heap overflow vulnerability that could lead to code execution (CVE-2011-2437).
Stack overflow vulnerabilities in the Adobe image parsing library that could lead to code execution (CVE-2011-2438).
Memory leakage condition vulnerability that could lead to code execution (CVE-2011-2439).
Use-after-free vulnerability that could lead to code execution (CVE-2011-2440).
Stack overflow vulnerabilities in the CoolType.dll library that could lead to code execution (CVE-2011-2441).
Logic error vulnerability that could lead to code execution (CVE-2011-2442).

Websense Security Labs and our ThreatSeeker Network are constantly monitoring for these threats occurring in the wild.

nb : websense Read More...

14/09/11

MS Patch Tuesday warning: Opening legitimate .doc, .txt files brings code execution risk

Microsoft today warned that innocuous documents, including legitimate rich text format files (.rtf), text files (.txt), or Word documents (.doc) could be used in code execution attacks against Windows users.

As part of this month’s Patch Tuesday release, Microsoft shipped MS11-071 to address a publicly known vulnerability in Windows Components that could be exploited via Office documents.

From the bulletin:

The vulnerability could allow remote code execution if a user opens a legitimate rich text format file (.rtf), text file (.txt), or Word document (.doc) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


The vulnerability is caused when specific Windows components incorrectly restrict the path used for loading external libraries, Microsoft explained.
Despite the risk of “remote code execution” attacks, Microsoft is rating this an “important” issue. The company says workstations and terminal servers are primarily at risk and warns that servers could be at more risk if administrators allow users to log on to servers and to run programs.

A separate bulletin (MS11-072) provides cover for a total of five documented vulnerabilities in Microsoft Office. The company said these vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file.
Microsoft’s flagship Office productivity suite is also affected by a third bulletin (MS11-073) that provides fixes for a pair of remote code execution vulnerabilities.
The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file or if a user opens a legitimate Office file that is located in the same network directory as a specially crafted library file.
This month’s Patch Tuesday batch also includes a fix for an elevation of privilege vulnerability in WINS
that could be exploited if a user received a specially crafted WINS replication packet on an affected system running the WINS service.

An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability, Microsoft said. Patches for this flaw was included in the “important” MS11-070 bulletin.

The company also issued a fix for a total of six vulnerabilities in Microsoft SharePoint and Windows SharePoint Services.

“The most severe vulnerabilities could allow elevation of privilege if a user clicked on a specially crafted URL or visited a specially crafted Web site,” Microsoft said.

For the most severe vulnerabilities, Internet Explorer 8 and Internet Explorer 9 users browsing to a SharePoint site in the Internet Zone are at a reduced risk because, by default, the XSS Filter in Internet Explorer 8 and Internet Explorer 9 helps to block the attacks in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9, however, is not enabled by default in the Intranet Zone.
  
nb : zdnet
Read More...