republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
4777
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3 · 4
AuthorAll Replies


Zhen-Xjell
Prolific Bunny
Premium,VIP,ExMod 2001-04
join:2000-10-08
Bordentown, NJ

Executing arbitrary commands without Active Script

Any application that hosts the WebBrowser control (5.5+) is affected since this exploit does not require Active Scripting or ActiveX. Some of these applications are:

-Microsoft Internet Explorer
-Microsoft Outlook
-Microsoft Outlook Express

»security.greymagic.com/adv/gm001-ie/



Of particular interest, while running Proxomitron nothing was executed on the test pages via the supplied link above.
--
Join a Distributed Computing Team at DSLR Today! Cure AIDS, Cancer, Diabetes, Alzheimer's and more!


jansson_mark
Markus Jansson
Premium
join:2001-08-05
Finland

IE again? Am I surprised?

AAAAAAAAAAAAAAARRRRRRRRRRRRRRRRRRRRRGGGGGGGGGGGGGGGGGHHHHHHHHHHHHHHHHHHHHHHHH!!!

IE. Again. But this time without javascript! WOW!
But Opera6.01 is immune! Hahahhahhaa!:D

Thanks for letting us know.
--
My privacy related homepage & PGP keys:»www.markusjansson.net


IamZed
Premium
join:2001-01-10
Dayton, OH

reply to Zhen-Xjell

Re: Executing arbitrary commands without Active Script

Nothing happens here.


R2
R Not
Premium,MVM
join:2000-09-18
Long Beach, CA
kudos:1

reply to Zhen-Xjell
Interesting as always. The tests only work on NT/2K/XP, so I cannot test this old Win98 box...



PapaDos
Cum Grano Salis
Premium,MVM
join:2001-02-08
Lasalle, QC
kudos:2

R2, you can test for 98 box by specifying the application yourself.
And yes the app will run on 98 boxes...
--
Nunc est bibendum...



R2
R Not
Premium,MVM
join:2000-09-18
Long Beach, CA
kudos:1

You are completely correct. Notepad opened with C:/Windows/Notepad.exe in the Run line.

Here is the *exact* packet that I received to run this:

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Thu, 28 Feb 2002 18:55:29 GMT
Content-Length: 583
Content-Type: text/html
Cache-control: private

<html>
….<head>
…….<title>Running "C:\Windows\notepad.exe"
…….</title>
…….<link rel="stylesheet" href="../sec.css">
….</head>

….<body>
…….Running "C:\Windows\notepad.exe"
…….<span datasrc="#oExec" datafld="exploit" dataformatas="html">
…….</span>
…….<xml id="oExec">
……….<security>
………….<exploit>
…………….<![CDATA[
…………….<object id="oFile" classid="clsid:11111111-1111-1111-1111-111111111111"
………………codebase="C:\Windows\notepad.exe">
…………….</object>.....]]>
………….</exploit>
……….</security>
…….</xml>

…….<form method="post">
……….<input type="text" name="oProg">
……….<input type="submit" id="oCheck" value="Run">
…….</form>
….</body>
</html>
[text was edited by author 2002-02-28 14:10:41]



bangaroo
Premium
join:2000-08-13

reply to Zhen-Xjell

Click for full size
Very disturbing.
Now I am really nervous:(.

NotePad will also execute on my WinMe system.

I am not sure if it is important or interesting, but when I entered notepad.exe into the RUN box (instead of the full path C:/Windows/Notepad.exe), I got the above message.
[text was edited by author 2002-03-01 05:34:15]


Jason Levine
Premium
join:2001-07-13
USA

said by contango:
Very disturbing.
I am not sure if it is important or interesting, but when I entered notepad.exe into the RUN box (instead of the full path C:/Windows/Notepad.exe), I got the above message.
[text was edited by author 2002-03-01 05:34:15]

I got that dialog box too. Of course the simple test didn't work for me as it was trying to execute c:\winnt\system32\calc.exe and I have Windows installed on the D drive.

Some followup. I played with my security settings until the notepad launch was allowed. Atached it a screenshot of the security setting you can change to defeat this. Simply set "Download unsigned ActiveX controls" to Disable or Prompt. If it's "Enable" then the program can be launced without your approval.

[text was edited by author 2002-03-01 12:52:16]


R2
R Not
Premium,MVM
join:2000-09-18
Long Beach, CA
kudos:1

With everything set to Disabled (i.e., all ActiveX), I get that same ActiveX warning box if -- and only if -- I enter the WRONG path in Run. If I enter the correct path, then Notepad, or Calculator, or whatever runs.

The packet I receive from the page is EXACTLY the same as I posted above. So the response is from my computer. My guess is that the [object id="oFile" classid="clsid:11111111-1111-1111-1111-111111111111"] line must trigger ActiveX to try to download a control -- IF the program listed cannot be located.

I am not sure I understand that completely.:(
_____________

Silly side note: I always wondered what the source of that ActiveX Message Box was and I found it: shdoclc.dll

[text was edited by author 2002-03-01 15:59:58]


TheWiseGuy$
Dog And Butterfly

join:2001-08-11
Yonkers, NY

reply to Zhen-Xjell
With Netscape 4.79 it didn't open notepad but with IE5.5SP2 notepad opened. Like R2 I have everything turned off except submit nonencrypted form data. I'm using Windows ME so I had to put in the path. Now that is a vulnerability.
[text was edited by author 2002-03-01 14:26:24]



kdog41

join:2002-02-20
Trenton, MI

reply to Zhen-Xjell
Strange,

All I get is the following:

Running "c:/winnt/system32/calc.exe"..

I check in task manager and nothing is running. when I try the advanced window I get a run box but again nothing happens.

I just realized the path is wrong. XP Home edition doesn't use the winnt directory.
The advanced one will work if you put the complete path in the directory. I also have unsigned ActiveX disabled and signed ActiveX for prompt and it still runs with the complete path in the run box. The question is can someone manipulate the code to type in the run box and click run?

[text was edited by author 2002-03-01 14:51:54]


TheWiseGuy$
Dog And Butterfly

join:2001-08-11
Yonkers, NY

reply to Zhen-Xjell
Interesting it won't open Netscape.exe and while it will open hdown.exe, a filedownloader, it won't open it with command parameters. I wonder why.



BlitzenZeus
Burnt Out Cynic
Premium
join:2000-01-13
kudos:2

reply to Zhen-Xjell
This is very bad

[text was edited by author 2002-03-01 16:23:04]



Zhen-Xjell
Prolific Bunny
Premium,VIP,ExMod 2001-04
join:2000-10-08
Bordentown, NJ

said by BlitzenZeus:
This is very bad
Not unless you're running Proxomitron.


Murray3

join:2001-03-06
Texas

reply to Zhen-Xjell
There is a registry tweak which may help with this...

Disable Access to File URLs in Internet Explorer (All Versions)
Key: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
Value Name: NoFileUrl
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = Enable File URLs, 1 = Disable)


(The NoFileURL key will probably need to be added).

Of course, to those who are not confident or familiar with making Registry edits, you'd be advised to backup the Registry before adding/editing to it... and if in any doubt, don't make any Registry Changes.

The tweak should be able to prevent IE from opening any files and executables. It should limit IE to opening only URLs.

Of course, it still doesn't take away the fact this is still a problem with IE. Just thought I'd offer a suggestion for those who may be interested.

Edit: Ignore this tweak. Having tested the vulnerability, it still exists following editing this tweak into the registry. Sorry.

[text was edited by author 2002-03-01 17:24:23]



BlitzenZeus
Burnt Out Cynic
Premium
join:2000-01-13
kudos:2

Sorry Murray, it doesn't work...



Murray3

join:2001-03-06
Texas

said by BlitzenZeus:
Sorry Murray, it doesn't work...
I just tried it too for the first time... and you're on the mark.

Sorry for the mis-info... Bang goes my thought for a quick fix!

[text was edited by author 2002-03-01 17:27:39]


Zhen-Xjell
Prolific Bunny
Premium,VIP,ExMod 2001-04
join:2000-10-08
Bordentown, NJ

Do I sense Proxo converts?


dminer

join:1999-12-11
San Francisco, CA

reply to Zhen-Xjell
Here is the fix that I found on the GRC.com discussion group. First, you need to make the security settings for My Computer visible in Internet Explorer. Then you need to disable downloading unsigned ActiveX controls in the My Computer zone. To make the My Computer security zone visible. Set the value of the following registry key to "3":

HKCU\Software\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\Flags

Then go to IE's security settings. You will see a new zone called My Computer. Disable downloading unsigned ActiveX controls. You might also want to disable scripting of unsafe ActiveX controls while you are at it.

If you have already run the test, you should delete the ActiveX control that was silently downloaded into your Downloaded Program Files subdirectory of your windows directory. The control to delete is the one with all the 1's in its name.

That fixes it!

--Mathew Chacko



bangaroo
Premium
join:2000-08-13

reply to Zhen-Xjell
Zhen, any ideas how Proxo stops the .exe files from executing?
Murray's reg hack apparently didn't work, but the solution could still be somewhere in the registry?

Jason, here is a new project for you!
Wouldn't it be wonderful if Script Sentry could save our souls

page: 1 · 2 · 3 · 4

Monday, 04-Jun 05:58:41 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics