Pavlov Scope

2006 January 3

New Blackberry Vulnerabilities

Filed under: ITSec — Kev Frey @ 15:47:31

Hi all;

For those of you with Blackberry devices or those of you responsible for running Blackberry Enterprise Servers, take note. At least one (or more) vulnerabilities have been discovered by security researcher “FX” (Felix Lindner) in the way that the handhelds and server render graphics files (specifically, for now, TIFFs and PNGs). More information is available at Brian Krebs’s excellent blog.

If you are responsible for BES servers in your organization, I recommend disabling all image file types from the Attachment service for the time being.

_____________________________________________________________
KevFrey

kevfrey@gmail.com
.     .    .   .  . .. .  .   .    .     .

WMF Exploit (Update4)

Filed under: ITSec — Kev Frey @ 12:02:31

Hi again;

Word from Redmond:

Microsoft has released additional information – The problem is scheduled to be addressed on the normal patch cycle (generally the first Tuesday of every month), which in this case is 10/January/2006. So, get your Automatic Updates configured if you haven’t already.

Additionally, new information clarifying the vulnerable operating system versions has surfaced.

However, I still recommend installing Ilfak’s “unofficial” hotfix (v1.4) for this problem for the next week of operation.
Then, once the fix has been deployed, uninstall Ilfak’s fix, reboot, then pull down and install the Microsoft fix, reboot.
Then use Ilfak’s vulnerability checking tool to verify that the fix from Microsoft resolved the problem.

_____________________________________________________________


KevFrey

kevfrey@gmail.com
.     .    .   .  . .. .  .   .    .     .

WMF Exploit (Update 3)

Filed under: ITSec — Kev Frey @ 1:23:31

Hiya;

Another update. Ilfak has posted a new version (v1.4) that provides silent install capabilities.

Using the old (1.3) version, one can use Active Directory’s Software Installation (in the Computer section). But, this one (v1.4) adds scripting and built-in silent installation and related switches during install.

_____________________________________________________________


KevFrey

kevfrey@gmail.com
.     .    .   .  . .. .  .   .    .     .

2006 January 1

WMF Exploit (Update 2) - Even worse

Filed under: ITSec — Kev Frey @ 17:30:31

Yet another development… It is getting worse before it is getting better.

Now, like the polymorphic viruses of old, the exploit has become even harder to defend against. SANS has posted a new alert describing the latest iteration of the WMF unpatched vulnerability.

The gist is that the attack code “looks” a little different every time. Since the vulnerability remains unpatched, the primary defense against this flaw has been antivirus (AV) software. The way nearly all AV works is by generating a unique string of information (known as a signature) to spot malicious code. But, since this attack changes slightly in a random way each time, AV signature methods won’t work the same way, making the exploit that much more difficult to detect.

I recommend immediately running the regsrv32 command (as follows) to divorce the automatic execution of this exploit:

  1. Choose Start, then Run from the taskbar.
  2. Type regsvr32 /u shimgvw.dll and click OK when the confirmation dialog appears.

Secondly, in your email software I strongly suggest turning off (disabling) the automatic rendering of inline images and embedded links if available in your mail client settings.

Additionally, a person named Ilfak Guilfanov has reverse engineered the vulnerable code and has released a patch that appears to resolve the problem. I have not tested this yet myself, but have no reason to think that it won’t work. However, on your work computers (i.e. the one’s provided and mantained by your employer), unless you have prior approval, do not run this fix because it might interfere with the forthcoming fix from Microsoft when deployed. Ilfak has stated on the blog to uninstall this fix prior to installing the fix from MS when it comes available.

Ugly, ugly attack. Happy friggin’ New Year ;-) Questions or problems, please let me know.

_____________________________________________________________
KevFrey

.     .    .   .  . .. .  .   .    .     .
« Previous Page