On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 43 of 72:
Next »
« Previous
Better yet, here is the e-mail from Thor Larholm:
Reprinted in its entireity:

Despite the severity of some of the vulnerabilities posted by Liu Die
Yu, such as the ability for system compromises, it is relatively easy to
mitigate against the impact and even prevent them from having any effect
at all.

Much ado has been made about those vulnerabilities and they have been
covered in numerous places such as Forbes, NY Times and CNN. What this
tells me is that we need a radically different approach than the status
quo. One such approach is to put more emphasis on education and secure
coding, so that we can reliably prevent future threats. Another such
approach is to focus on proactive security measures that prevent
vulnerabilities and design flaws from having any effect in advance,
prior to their discovery and publication. We can recognize the common
pathways that these vulnerabilities rely on and act accordingly.

When I attended the NTBugtraq Retreat earlier this year, most of the
attendees were surprised to hear that I am using Internet Explorer on a
daily basis, particularly since I should know how vulnerable it can be
at any given time. I surf with JavaScript and ActiveX enabled, see flash
movies and play Java games, but despite this I am not vulnerable [0] to
a single command execution vulnerability or system compromise through
Internet Explorer.

How, you might ask? Simple, I have locked down the My Computer security
zone on my installations [1].

Each and every command execution vulnerability in Internet Explorer over
the last few years have all depended on the functionality of local
security zones. Whenever you are crafting an exploit, you want to
navigate a window object to a local security zone, inject some scripting
or HTML into the window object and subsequently use the features of the
local security zone to execute your payload. Properly locking down the
My Computer zone prevents all of these from having any effect.

However, changing the Internet Explorer security zone settings is not a
nimble task. Despite being partly split after IE4, the functionality of
Windows Explorer and Internet Explorer is still very tightly interwoven.
If you are not careful you WILL cause your system to malfunction and no
longer open Explorer folders, launch applications or even boot into
Windows properly. You need to strike a very sensible balance.

During the course of our research, we crafted and tested solutions to
this problem on tens of thousands of installations and have beta tested
on thousands of users, and have incorporated the results into our FREE
constantly updated Proactive Threat Mitigation application that goes by
the name of Qwik-Fix(r) ( www.pivx.com/qwikfix/ ). Our beta users were
never affected by Blaster, HTAExploit or MiMail - to name a few.

Now, let's analyze the vulnerabilities Liu Die Yu posted on November
25th [2], as there was not much details in the post.

"1stCleanRc" is not a vulnerability of its own, but an example exploit
detailing how to combine the "MhtRedirParsesLocalFile",
"BackToFramedJpu" and "MhtRedirLaunchInetExe" vulnerabilities. The same
goes for "execdror6" which is an example exploit that relies on the
"LocalZoneInCache" vulnerability, as well as "LocalZoneInCache" which is
a demonstration of using "threadid10008".

This leaves us with 5 vulnerabilities to analyze:

MhtRedirParsesLocalFile is designed to display and parse a locally
residing file of any plaintext format in an IFRAME. On most of our
installations we could only reproduce the display part. Still, being
able to display a locally residing file in a window object is
specifically prohibited by IE6 SP1.

MhtRedirLaunchInetExe expands a bit on the capabilities of the codeBase
vulnerability. Microsoft fixed codeBase in the Internet Zone, but left
it in the My Computer zone. As such, MhtRedirLaunchInetExe simply makes
it one step easier to bundle HTML, Script and executable payload in the
same file.

BackToFramedJpu lets you inject javascript URLs into the history and
have them executed in the context of the target window object.

HijackClickV2 lets you hijack clicks and target them at some system
dialogs. You will have to know the location of those.

Threadid10008 is intended to download an HTML file to the TIF and
subsequently display and parse it. It could not be reproduced on all our
systems, but it does help leverage entry into a local security zones on
the installations it worked on.

Locking down the My Computer security zone prevents all of the 3
exploits by mitigating the effects of the remaining vulnerabilities
substantially, while still allowing a usable surfing experience.

As a final comment, I do believe that vulnerability researchers should
notify vendors of potential vulnerabilities and give them some time to
fix these before exposing the public to the dangers of those
vulnerabilities. Posting demonstratory proof-of-concept code has served
to apply pressure in the past towards unresponsive vendors, but not
giving the vendors any chance to respond at all in the first place is
simply irresponsible and jeopardizes the security of the Internet as a
whole.


References:

[0] Qwik-Fix(r)
http://www.pivx.com/qwikfix/

[1]
Description of Internet Explorer Security Zones Registry Entries
http://tinyurl.com/ubfq

[2] Post by Liu Die Yu
http://tinyurl.com/x8qx



Regards

Thor Larholm
Senior Security Researcher
PivX Solutions
24 Corporate Plaza #180
Newport Beach, CA 92660
http://www.pivx.com
thor@pivx.com
949-231-8496

PivX defines "Proactive Threat Mitigation". Get a FREE Beta Version of
Qwik-Fix
Posted by: Confused by religion   Posted on: 01/07/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

My laptop are secured all the time!  GraysonPeddie | 01/06/04
Ego BLOW  angvil | 01/06/04
XP?  JWatson77 | 01/07/04
My PC's are secured all the time!  amigatec | 01/07/04
Good to know  oliviera@... | 01/12/04
How does it feel...  MkIIISupra | 01/07/04
My laptop is secured all the time too!  kray_z | 01/07/04
My loptop IS THE SECUREIST!  Tammee | 01/07/04
At what price?  Cardinal_Bill | 01/07/04
My laptop comes pre-installed with Windows XP.  GraysonPeddie | 01/07/04
By the way, please note...  GraysonPeddie | 01/07/04
Toshiba?  MkIIISupra | 01/07/04
Well said  oliviera@... | 01/12/04
new year, same story  stephen732@... | 01/06/04
DEAR MR puma  angvil | 01/06/04
most not happy  JWatson77 | 01/07/04
this has to do with the OS 90% of the people are using and 90% of the peopl  guitar player | 01/07/04
do you get out much  JWatson77 | 01/07/04
um yeah  voska | 01/07/04
Somebody want to get that guy the Netcraft link?  Jose Jimenez | 01/07/04
new year, same story  PmAc_z | 01/07/04
huh?  Your Daddy | 01/07/04
my thoughts  voska | 01/07/04
Microsoft does it again...  Mike Cox | 01/06/04
MS IS expert at marketing innovations  Franklin_z | 01/07/04
Awe, come on Mike!  BitTwiddler | 01/07/04
re : ms releases fix that should of been released tlast year  JWatson77 | 01/07/04
I'm still waiting on the December 2003 Patches  nucrash | 01/07/04
Oh, yeah, that one....  Confused by religion | 01/07/04
and ms still has not fixed  JWatson77 | 01/07/04
Try again...  libertyaikido | 01/08/04
ms need to get rid of this before  JWatson77 | 01/07/04
These people need to lose their internet account!  Tammee | 01/07/04
Reverse the Order  ShadeTree | 01/07/04
Login script...  Domb2 | 01/07/04
Good idea but..  Domb2 | 01/07/04
AOL already disables Messenger Service  paman57@... | 01/07/04
You're Kidding ... Right?  coffeenite | 01/07/04
thats not what I said  Tammee | 01/07/04
23 Unpatched Internet Explorer Vulnerabilities  David Mohring | 01/07/04
Yet Thor still uses IE  Confused by religion | 01/07/04
A real link would be nice  Taz_z | 01/07/04
Better yet, here is the e-mail from Thor Larholm:  Confused by religion | 01/07/04
That kind of answers the first part  Taz_z | 01/07/04
mozilla doesn't put my pc at risk  JWatson77 | 01/07/04
Thor who?  GRindinAxTaRupy | 01/07/04
No. The Thor who works for a company that has Microsoft as a client  Taz_z | 01/07/04
I have tried Mozilla - didn't like it  Confused by religion | 01/07/04
What didn't you like about it?...  GRindinAxTaRupy | 01/07/04
Contrary to popular opinion...  Confused by religion | 01/08/04
There are NO "safe" platforms to use on the internet  Dragon_z | 04/05/04
So what!  NT Admin | 01/07/04
Trustworthy computing = We close the barn door  Squawkbox | 01/07/04
Why I prefer Linux over Windows  noShut_z | 01/07/04
yeah like  JWatson77 | 01/07/04
Easy...  noShut_z | 01/07/04
Sure Buddy  FreeBSD | 01/07/04
"Buddy, I like the sound of that....  noShut_z | 01/07/04
Fully functional  FreeBSD | 01/07/04
Another rule of thumb..  FreeBSD | 01/07/04
And...  FreeBSD | 01/07/04
Thanks for the advice?  noShut_z | 01/07/04
While I'm at it...  noShut_z | 01/07/04
While I have time and am in the mood to post...  noShut_z | 01/07/04
Licensing - but not what you're thinking  lfereday | 01/07/04
WARNING: Read the EULA first!!!  No_Ax_to_Grind | 01/07/04
A lot of us are...  BitTwiddler | 01/07/04
Yikes! Is this still you Bitty?..  GRindinAxTaRupy | 01/07/04
Unlike some children...  No_Ax_to_Grind | 01/07/04
So you finally admit to being a child?  B.O.F.H. | 01/07/04
I resemble that comment...  Jack-Booted EULA | 01/07/04
Hmmm  ghandalf | 01/07/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
New Online Dashboard for IT Leaders
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
Learn more >>
Business Value of Windows Server 2008 R2 Hyper-V and Live Migration.
Today's IT departments are under increasing pressure to manage and support expanding computer resources while reducing costs. See how Windows Server 2008 R2 is making this process seamless.
Click to download >>
advertisement

IT Solutions for 2010

  • Get cost-effective strategies and roadmaps on the most important issues facing IT leaders in 2010! Learn how to easily cut costs and deliver greater efficiency starting with your database, IT compliance management and data center. Visit the IT Leaders Dashboard. Visit the IT Leaders Dashboard.
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline