<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; exploit</title>
	<atom:link href="http://www.spamchronicles.com/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Computer Security Logs</description>
	<lastBuildDate>Tue, 05 Oct 2010 22:13:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Vulnerability Pits Firefox Against IE</title>
		<link>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/</link>
		<comments>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/#comments</comments>
		<pubDate>Tue, 10 Jul 2007 22:52:23 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[internet-explorer]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/vulnerability-pits-firefox-against-ie/</guid>
		<description><![CDATA[A new zero-day vulnerability exists when both Firefox 2.x and Internet Explorer are installed on the same machine. The exploit is most likely to be available on PCs with Firefox 2.0.0.2 installed due to changes made for Microsoft Vista compatibility. The general consensus of the comments are that both applications contribute the the exploit. Firefox [...]]]></description>
			<content:encoded><![CDATA[<p>A new <a title="Jump to to the entry on Larholm.com" href="http://larholm.com/2007/07/10/internet-explorer-0day-exploit/">zero-day vulnerability</a> exists when both Firefox 2.x and Internet Explorer are installed on the same machine. The exploit is most likely to be available on PCs with Firefox 2.0.0.2 installed due to changes made for Microsoft Vista compatibility.</p>
<p>The general consensus of the comments are that both applications contribute the the exploit. Firefox is the attack vector and fails to validate the malicious code but Microsoft contributes by not properly passing quotes to the command line. You need to visit a malicious website using IE in order to trigger the exploit.</p>
<p>In a response to a user comment Thor Larholm responded:</p>
<blockquote><p>&#8230; Firefox is the current attack vector but Internet Explorer is to blame for not escaping ” (quote) characters when passing on the input to the command line. I agree that Firefox could have registered its URL handler with pure DDE instead and thereby have avoided the possibility of a command line argument injection, but IE should still be able to safely launch external applications safely.</p></blockquote>
<p>What I find interesting is the complexity of the requirements leading to the exploit. Neither product is vulnerable alone since both must be installed and both products have a flaw that contributes to the vulnerability.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/" rel="bookmark" class="crp_title">Mac Hacked &#8211; Both Sides Miss the Point</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Hacked &#8211; Both Sides Miss the Point</title>
		<link>http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/</link>
		<comments>http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/#comments</comments>
		<pubDate>Wed, 25 Apr 2007 23:38:17 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[mac]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/commentary/mac-hacked-both-sides-miss-the-point/</guid>
		<description><![CDATA[One of two MacBooks was hacked at the CanWestSec conference is Vancouver, Canada. Both Macbooks were part of the &#8220;hack-a-Mac-contest&#8221; at the show. A successful hacker got the Macbook. The Macbooks were set up with OS X and all the latest security updates (including 2007-004) but no additional security software or special settings. One of [...]]]></description>
			<content:encoded><![CDATA[<p>One of two MacBooks was hacked at the CanWestSec conference is Vancouver, Canada. Both Macbooks were part of the &#8220;hack-a-Mac-contest&#8221; at the show. A successful hacker got the Macbook. The Macbooks were set up with OS X and all the latest security updates (including 2007-004) but no additional security software or special settings.</p>
<p>One of the Macs was hacked on the second day, which made headlines (in the types of publications that care about such things). The headlines tended to be slanted in one of two directions. Some emphasized that Mac security was breached and equated it to the worst windows vulnerabilities. They left out the details. On the other side the articles were slanted towards the fact that the breach only occurred after the rules were relaxed and that the breach didn&#8217;t get root access. This was true and more detailed than the sensational headlines in the first category, but they tended to imply the breach was meaningless.</p>
<p>The facts are:</p>
<ul>
<li>The Mac was breached when it visited a malicious website</li>
<li>The vulnerability is in Quicktime (Initial reports that it was a vulnerability in Safari were wrong.)</li>
<li>Both Firefox and Safari could be used to deliver the vulnerability</li>
<li>Windows is also considered vulnerable (if it has Quicktime)</li>
<li>The vulnerability was found by a security researcher and the exploit was actually delivered by a friend of his. The friend is keeping the MacBook, the researcher is applying for the $10,000 bounty offered by TippingPoint.</li>
<li>A second Mac, which required a hacker to get root/administrator level access and did not surf the web was not breached.</li>
</ul>
<p>What does this all mean, if anything?</p>
<p><span id="more-35"></span></p>
<p>Starting at the top, it was necessary to visit a website to be breached. The OS used doesn&#8217;t affect whether or not a person visits a website. So social engineering is universally available to every OS with a web browser. (I&#8217;ll avoid the path which talks about which OS has &#8220;smarter&#8221; users.) The best that can be said is that since there&#8217;s more windows users they&#8217;re more likely to be affected if the vulnerability is OS specific. But do exploits have to be OS specific?</p>
<p>The vulnerability was in Quicktime which is essentially a third party app. I don&#8217;t say this to claim OS X wasn&#8217;t hacked. Apple created Quicktime and delivers it with every new Mac. Apple is responsible for it and for updating it. But Quicktime is essentially a 3rd party app made by the same company as the OS so it&#8217;s bundled. The vulnerability is also thought to exist in the Windows version (for obvious reasons the exact details of the vulnerability aren&#8217;t public). The Macromedia (now Adobe) Flash Player is another 3rd party web-helper app that has had <a href="http://www.adobe.com/devnet/security/security_zone/mpsb05-07.html" title="Jump to an example of a Flash player vulnerability">vulnerabilities</a> in the past. OS venders can&#8217;t prevent vulnerabilities in 3rd party apps, the most they can do is mitigate their effect.</p>
<p>Both Firefox and Safari could be used to run the exploit. This isn&#8217;t surprising since the vulnerability was in Quicktime. But it does mean any modern browser could probably be used.</p>
<p>Windows, with Quicktime, is also vulernable (or it&#8217;s thought to be). By exploiting a vulnerbility in a third party app it&#8217;s possible to exploit multiple OS&#8217;s. The greatest number of PCs are still Windows so the payload delivered by the exploit might be Windows only if the hacker is lazy or just wants the biggest bang. But it&#8217;s not difficult to determine the OS used so it would be trivial to deliver an OS specific exploit for various OS&#8217;s through the same exploit. It&#8217;s just a matter of writing each exploit.</p>
<p>The exploit was found as part of a contest with a prize of a Macbook and was submitted for a $10K prize. Year&#8217;s ago it might have been enough to be able to claim bragging rights. Now money is a prime motivator. Money motivates hacking for both good (bounties, paychecks) and for bad (sell spam distribution, steal passwords). An OS will be targeted when the financial rewards justify the efforts.</p>
<p>Root level access was not obtained, &#8220;only&#8221; user level access. While this may be the best a current OS can do when a 3rd party app is hacked it still does not mean we aren&#8217;t at risk. Programs installed into the user&#8217;s folders do not require a password to install and run. As Windows PCs become more secure hackers may have to learn to live with user-level hacks in the Windows world. Since that world is so large there&#8217;s a bigger financial reward for success. Once the lessons are learned there they will be trivial (low cost) to transfer to the OS X world. So while OS X may have a smaller user base (and therefore reward) the cost to hack OS X will also drop. Most of what hacker&#8217;s want is available though user level access, just easier when you can own the machine as an administrator. It just means you need to be signed on (unless they find a way around that) but many PCs and Macs use auto logons and most PCs stay always logged on when ever they are turned on.</p>
<p>Of course, the old unavoidable hacks persist as evidenced by the recent animated cursor exploit for which we were defenseless for awhile and could be exploited without us having to click anything (although receiving an email or going to a website were still required). But their numbers are decreasing.</p>
<p>I wouldn&#8217;t be surprised to learn that a PC installed with Vista (latest patches, additional software or settings) would be as secure as OS X. But what will bite Microsoft is that they don&#8217;t control the installations, the resellers do. Since tight security means more support calls (which go to the vendor, not to Microsoft) I wouldn&#8217;t be surprised to learn that what&#8217;s actually shipping is not as secure as it should be.</p>
<p>The best protection Mac users have is that there&#8217;s an extremely large population of vulnerable Windows machines out there and exploiting them is easy. In Windows XP Service Pack 2 Microsoft turned on the firewall by default. This made it much harder to just scan the internet looking for open ports to exploit and deliver a payload. This brought a drop in the spread of viruses through that method but an increase in other methods such as email and malicious websites. These are methods which require a user to take action (again, with some exceptions when a vulnerability can be exploited to bypass user action). With the firewall change the hackers changed their tactics to other profitable methods. I won&#8217;t be surprised to learn that web based attacks are becoming more sophisticated and will use cross-platform applications to exploit multiple OS. And as more applications work cross platform we&#8217;ll probably see more multiple OS aware attacks through their data files.</p>
<p>The good news is that Mac OS X has good security and Microsoft Windows is getting more secure as Microsoft learns it&#8217;s lessons. Us humans are now being targeted as the weak link but we do have control over where we browse and what email we open. The bad news is that there are still software vulnerabilities so that even the most careful of us are still at risk, although less risk than before.</p>
<p>The point isn&#8217;t which is more secure, OS X or Linux. The point is whether or not your computing habits and the software you use are secure. If they aren&#8217;t secure then no matter which OS you use it&#8217;s only a matter of time before you have problems.</p>
<p><a href="http://news.com.com/Mac++hacked+through+QuickTime+flaw/2100-1002_3-6178787.html" title="Jump to the news.com article about the Mac hack">News.com</a> has a good story about the hack that emphasizes the details instead of the hype.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/05/15/symantec-hackers-can-bypass-firewall-with-windows-update/" rel="bookmark" class="crp_title">Symantec: Hackers Can Bypass Firewall With Windows Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/06/summary-of-week-ending-may-5th/" rel="bookmark" class="crp_title">Summary of Week Ending May 5th</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li><li><a href="http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/" rel="bookmark" class="crp_title">Adobe Patches Flash Player</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows PC Have Cursor Hole</title>
		<link>http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/</link>
		<comments>http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/#comments</comments>
		<pubDate>Sun, 01 Apr 2007 01:58:32 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Spam Chronicles 1.0]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/windows/windows-pc-have-cursor-hole/</guid>
		<description><![CDATA[Microsoft released a security advisory about a flaw in animated cursors which would allow drive-by installs. Windows 2000 SP4 and all recent operating systems are affected, including Vista. IE 7 running on Vista would be protected by a drive-by install if is it running in protected mode. Also, Outlook 2007 uses Word to display messages [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released a <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx" title="Microsoft Security Advisory 935423">security advisory</a> about a flaw in animated cursors which would allow drive-by installs. Windows 2000 SP4 and all recent operating systems are affected, including Vista. IE 7 running on Vista would be protected by a drive-by install if is it running in <a href="http://www.microsoft.com/windows/products/windowsvista/features/details/IE7protectedmode.mspx" title="Info on protected mode from Microsoft's website">protected mode</a>. Also, Outlook 2007 uses Word to display messages in preview so it would not be vulnerable.</p>
<p>The only real protection from this vulnerability would be for Microsoft to release a patch. The next &#8220;patch Tuesday&#8221; is April 10th. [Updated 4/2: Microsoft has said they will release a patch on Tuesday 4/3]</p>
<p>There&#8217;s also a significant impact within e-mail. The microsoft security bulliten mentions e-mail as a method to exploit the vulnerabilty.</p>
<blockquote><p><strong>What might an attacker use this function to do?</strong><br />
An attacker could try to exploit the vulnerability by creating a specially crafted web page. An attacker could also create a specially-crafted email message and send it to an affected system. Upon viewing a web page, previewing or reading a specially crafted message, or opening a specially crafted email attachment the attacker could cause the affected system to execute code. While animated cursors typically are associated with the .ani file extension, a successful attack is not constrained by this file type.</p></blockquote>
<p><span id="more-20"></span></p>
<p>Even previewing the mail message in an preview pane could infect the machine. (See below for exceptions to this)</p>
<p>Microsofts recommendation for e-mail is: </p>
<blockquote><p>Microsoft has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they help block known attack vectors. When a workaround reduces functionality, it is identified in the following section. </p>
<p>• Read e-mail messages in plain text format if you are using Outlook 2002 or a later version, or Windows Mail to help protect yourself from the HTML e-mail preview attack vector. Microsoft Outlook 2002 users who have applied Office XP Service Pack 1 or a later version can enable this setting and view e-mail messages that are not digitally signed or e-mail messages that are not encrypted in plain text only.</p>
<p>Caveat: Reading e-mail in plain text on Windows Vista Mail does not mitigate attempts to exploit the vulnerability when Forwarding and Replying to mail sent by an attacker.</p>
<p>Note: Reading e-mail in plain text on Outlook Express does not mitigate attempts to exploit this vulnerability. Impact of Workaround: E-mail messages that are viewed in plain text format will not contain pictures, specialized fonts, animations, or other rich content. Additionally:</p>
<p>• The changes are applied to the preview pane and to open messages.</p>
<p>• Pictures become attachments so that they are not lost.</p>
<p>• Because the message is still in Rich Text or HTML format in the store, the object model (custom code solutions) may behave unexpectedly.</p></blockquote>
<p>Microsoft makes the usual recommendations of not reading e-mail from a source you don&#8217;t know. But addresses can be spoofed or faked so any vulnerabity like this (where just viewing the message could infect the pc is a problem). Turnng off the preview pane will prevent accidents. There&#8217;s really isn&#8217;t any protection until Microsoft releases a patch.</p>
<p>Here&#8217;s a video of what happens when the vulnerability is used for a DoS attack on a PC (video via <a href="http://uneasysilence.com/archive/2007/03/10132/" title="Jump to the article with the video on UneasySilence">UneasySilence</a>):</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2010/09/27/microsoft-out-of-band-patch-for-advisory-2416728/" rel="bookmark" class="crp_title">Microsoft Out of Band Patch for Advisory 2416728</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

