To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


EIT Planet's Security News
 Symantec Warns of New Security Breach
 Security Vulnerabilities Prove Increasingly Costly
 IPS Market Approaches $1 Billion

Security Products
 BugBopper (BugBopper)
 VBA Password Remover Tool (VBA Password Remover)
 VBA Password Remover Software (VBA Password Remover Software)
 Free keylogger download (Free keylogger download)
 Monitoring Software (Monitoring software)
 Retrieve Outlook 2007 Password (Retrieve PST Password)


Go Back   Antionline Forums - Maximum Security for a Connected World > Security Discussions > Security News

Security News This is where we can discuss the latest security news from around the globe!

Reply
 
Thread Tools Display Modes
Old December 10th, 2008, 04:54 PM   #1
Slartarama
Member
 
Slartarama's Avatar
 
Join Date: May 2008
Location: Pacific Northwest
Posts: 53
Slartarama will become famous soon enoughSlartarama will become famous soon enough
IE 7 0 Day EXploit

Those of you using or supporting IE 7 be wary:

http://isc.sans.org/diary.html?storyid=5458&rss
Slartarama is offline   Reply With Quote
Old December 10th, 2008, 04:58 PM   #2
westin
Gonzo District BOFH
 
westin's Avatar
 
Join Date: Jan 2006
Location: SW MO
Posts: 932
westin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond repute
Well, thats just great! [sarcasm implied]

Thanks for the heads up.
__________________
\"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"

-HST
westin is online now   Reply With Quote
Old December 11th, 2008, 01:12 AM   #3
t34b4g5
Moderator!™
 
t34b4g5's Avatar
 
Join Date: Sep 2003
Location: Australia.
Posts: 2,391
t34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond repute
Nice heads up.

interesting that it doesn't effect Vista users.
t34b4g5 is offline   Reply With Quote
Old December 11th, 2008, 06:24 AM   #4
HTRegz
Super Moderator
Know-it-All Master Beaver
 
Join Date: Jan 2003
Posts: 3,911
HTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond repute
Quote:
Originally Posted by t34b4g5 View Post
Nice heads up.

interesting that it doesn't effect Vista users.
I'm curious as to where you've seen mention of it not affecting Vista users?

From the Microsoft advisory: "Our investigation so far has shown that these attacks are against Windows Internet Explorer 7 on supported editions of Windows XP Service Pack 2, Windows XP Service Pack 3, Windows Server 2003 Service Pack 1, Windows Server 2003 Service Pack 2, Windows Vista, Windows Vista Service Pack 1, and Windows Server 2008."

The example exploit that SANS ISC discussed doesn't target Vista, most likely due to the limited attack surface of IE 7 in Protected Mode on Vista. It would be entirely possible, however, to target Vista with the vulnerability.

That being said... if you've got another article I'm unaware of.. I'd love to read it.

Side note, anyone wanting to look at the code (since it's been sanitized on the SANS ISC site) send me a PM.
__________________
IT Blog: .:Computer Defense:.
PnCHd (Pronounced Pinched): Acronym - Point 'n Click Hacked. As in: "That website was pinched" or "The skiddie pinched my computer because I forgot to patch".
HTRegz is offline   Reply With Quote
Old December 11th, 2008, 11:51 AM   #5
t34b4g5
Moderator!™
 
t34b4g5's Avatar
 
Join Date: Sep 2003
Location: Australia.
Posts: 2,391
t34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond repute
Ht when i read the alert earlier it didn't have anything about Vista. Only XP and Windows server03.

That being said, they have obviously updated the alert as more info has come to light, thus i was confused on why it wan't a issue for Vista users, but it was for the others..

*********************

Some interesting stuff, apparently some Chinese sec team accidently released the POC for this ie7 w@llh@x..
http://www.computerworld.com/action/...c=news_ts_head

but apparently
Quote:
but it appears some hackers already knew how to exploit the flaw. At one point, the code was traded for as much as US$15,000 on the underground criminal markets, according to iDefense, the computer security branch of VeriSign, citing a blog post from the Chinese team
Quote:
However, other information indicates that hackers already knew how it worked before the release. According to knownsec, a rumor surfaced earlier in the year about a bug in Internet Explorer, iDefense wrote. Information on the vulnerability was allegedly sold in November on the underground back market for US$15,000. Earlier this month, the exploit was sold second or third hand for $650, said iDefense, citing knownsec.
Eventually, someone developed a Trojan horse program -- one that appears harmless but is actually malicious -- that is designed to steal information related to Chinese-language PC games, a popular target for hackers.
Ouchie's
t34b4g5 is offline   Reply With Quote
Old December 11th, 2008, 05:32 PM   #6
SirDice
Just Another Geek
 
Join Date: Jul 2002
Location: Rotterdam, Netherlands
Posts: 3,329
SirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond repute
Nice analysis:

http://www.breakingpointsystems.com/...ive-by-sundays
__________________
Oliver's Law:
Experience is something you don't get until just after you need it.
SirDice is offline   Reply With Quote
Old December 12th, 2008, 03:05 AM   #7
HTRegz
Super Moderator
Know-it-All Master Beaver
 
Join Date: Jan 2003
Posts: 3,911
HTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond reputeHTRegz has a reputation beyond repute
Looks like this has been expanded to include IE6 and IE8 (beta).
__________________
IT Blog: .:Computer Defense:.
PnCHd (Pronounced Pinched): Acronym - Point 'n Click Hacked. As in: "That website was pinched" or "The skiddie pinched my computer because I forgot to patch".
HTRegz is offline   Reply With Quote
Old December 16th, 2008, 09:06 PM   #8
phernandez
Senior Member
 
phernandez's Avatar
 
Join Date: Aug 2003
Location: NYC
Posts: 246
phernandez is a splendid one to beholdphernandez is a splendid one to beholdphernandez is a splendid one to beholdphernandez is a splendid one to beholdphernandez is a splendid one to beholdphernandez is a splendid one to beholdphernandez is a splendid one to behold
Patch as soon as tomorrow (fingers crossed).

Advanced Notification:
http://www.microsoft.com/technet/sec.../MS08-dec.mspx
phernandez is offline   Reply With Quote
Old December 18th, 2008, 09:58 AM   #9
t34b4g5
Moderator!™
 
t34b4g5's Avatar
 
Join Date: Sep 2003
Location: Australia.
Posts: 2,391
t34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond repute
Wink

Quote:
Originally Posted by phernandez View Post
The update notice on all the machines at work. We spent the day rolling this out and re-building image after image.

A few machines seem to off got bitten
t34b4g5 is offline   Reply With Quote
Reply

Bookmarks

Tags
exploit, internet explorer, kb960714, microsoft, ms08-078, patch, vulnerability, zero day

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Again.. Second 0-day exploit out... dalek Microsoft Security Discussions 7 September 23rd, 2006 03:46 AM
Exploit already available for Windows vulnerability Black Cluster Microsoft Security Discussions 3 October 14th, 2005 08:44 AM
Network Security made easy? Tiger Shark Microsoft Security Discussions 5 January 14th, 2005 07:47 PM
Cloaked Exploit Scanner II ntsa The Security Tutorials Forum 3 July 21st, 2002 04:00 PM
OE/IE6/WMP Temporary File Exploit zigar Microsoft Security Discussions 3 April 4th, 2002 07:50 PM


All times are GMT +1. The time now is 03:47 PM.












Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.