JPEG Vulnerability after patch!
Bottom line : the exploit still runs on my computer, after i have patched my machine! help!
Details :
I use WinXP SP1.
I have download and "patched" my machine from here :
http://www.microsoft.com/technet/sec.../ms04-028.mspx
(File called WindowsXP-KB833987-x86-ENU.EXE)
After I have patched my comp, I compiled the local exploit from here :
[edit : was a link to GDI+ buffer overrun exploit by FoToZ]
and its still working! its running cmd.exe as soon as i view the folder with the picture.
Plz Help! :(
<GDI scan results>
Scanning Drive C:...
C:\Program Files\Camera Suite\PhotoImpression\Share\gdiplus.dll
Version: 5.1.3097.0 <-- Vulnerable version
C:\Program Files\Common Files\Microsoft Shared\Office10\MSO.DLL
Version: 10.0.3311.0 <-- Possibly vulnerable (Under OfficeXP only)
C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll
Version: 6.0.2800.1106 <-- Possibly vulnerable (Win2K SP2 and SP3 w/IE6 SP1 only)
C:\WINDOWS\$NtServicePackUninstall$\sxs.dll
Version: 5.1.2600.0 <-- Vulnerable version
C:\WINDOWS\$NtServicePackUninstall$\vgx.dll
Version: 6.0.2600.0 <-- Possibly vulnerable (Win2K SP2 and SP3 w/IE6 SP1 only)
C:\WINDOWS\$NtUninstallKB839645$\sxs.dll
Version: 5.1.2600.1106 <-- Possibly vulnerable (Backup for uninstall purposes)
C:\WINDOWS\LastGood\System32\sxs.dll
Version: 5.1.2600.1106 <-- Vulnerable version
C:\WINDOWS\ServicePackFiles\i386\sxs.dll
Version: 5.1.2600.1106 <-- Vulnerable version
C:\WINDOWS\ServicePackFiles\i386\vgx.dll
Version: 6.0.2800.1106 <-- Possibly vulnerable (Win2K SP2 and SP3 w/IE6 SP1 only)
C:\WINDOWS\system32\sxs.dll
Version: 5.1.2600.1515
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13\GdiPlus.dll
Version: 5.1.3097.0 <-- Possibly vulnerable (Windows Side-By-Side DLL)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.10.0_x-ww_712befd8\GdiPlus.dll
Version: 5.1.3101.0 <-- Possibly vulnerable (Windows Side-By-Side DLL)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.1360_x-ww_24a2ed47\GdiPlus.dll
Version: 5.1.3102.1360
Scan Complete.
</GDI scan results>
PS : No, I dont want to upgrade to SP2.
You're Not Fully Patched ...
Quote:
Posted by STeRoiD
PS : No, I dont want to upgrade to SP2.
Why not? Perhaps you have a "Hot," copy of Windows XP and are worried about the consequences of installing SP2? ;)
Are you using XP home or XP Pro?
If you're serious about security you should install SP2!
Silly question ... Did you re-load Windows after installing the patch?
Anyone out there know if the patch linked to in STeRoiD's post is dependent on other patches? There's no mention of dependencies on the page linked to.
I Can See Your Point STeRoiD ...
Quote:
Originally posted by STeRoiD
First, although I think its valid, I removed the public exploit link because of the discussion.
I'd have left it. I can't see a problem with it, after all it's public. ;)
Quote:
Ok, SP2 improves your security. Actually I didnt install it because all of the problems I heared about the product, but now maybe I will install it... but thats not the point : Does anyone who have XP SP1 MUST to install SP2? I mean, isnt microsoft supposed to support the SP1 community either (which means, amongst other things, suply a *working* patch for it)?
Myabe it has to do with the article "Microsoft: To secure IE, upgrade to XP"
http://news.com.com/Microsoft+To+sec...3-5378366.html
But seriously, I dont see any reason why XP SP1 will still be vulnerable.
Given that SP2 implements fixes at kernel level, etc, I consider it essential! Yes, some people have had problems, but if the proper precautions are taken (backups anyone) then they're not insurmountable. Install SP2
If XP SP1 is not vulnerable, why did Microsoft release SP2? Can you see why XP SP1 is vulnerable now? :)
Microsoft Support a fully patched XP. First thing they will recommend is get to the latest patch level. The patch for SP1 is SP2! lol