Wednesday, 10 March 2010

IE6: Another serious vulnerability

Well, you had your chance.... Chances for that matter. It's really time to upgrade to IE8.... Today!

Microsoft has just released another security advisory for IE6 that allows Remote Code Execution yesterday which can be found here:


The reason I say you have had your chance (or in this case chances) Microsoft released an update in January to mitigate this issue hefty (which is now in the wild) as Jerry Bryant from Microsoft Security team highlights;

"At this time, we are aware of targeted attacks seeking to exploit this vulnerability against Internet Explorer 6. Internet Explorer Protected Mode in Internet Explorer 7 running on Windows Vista helps to mitigate the impact of this issue. "

Meaning, that this exploit is now in the wild, and if you are running IE6 or the standard configuration of IE7, you are now pretty vulnerable to  attack.

You can find the Microsoft Security update MS010-002 here:

And for a description of the issue and some of the risks associated with this latest (greatest) IE6 issue you can read the CVE details here:


And, if you need to fix the issue (by enabling and turning DEP for IE) you can choose the Microsoft "Fix IT" (sounds familiar??) option here:


Note: this Microsoft Fix-IT approach will download an MSI onto your desktop. This Microsoft Installer package (MSI file) will update your local compatibility database with SDB file that will switch on DEP for your browser. Note: Enabling DEP may cause application issues for other applications and within IE itself.

Or, you could just upgrade to IE8 then..



Tuesday, 9 March 2010

2010: The year we make contact: ...with the global economy

As you can probably tell - life is doing a bit of "number" on me right. Trying to get the right priorities in the right order - work/family/me/work... yeesh. When you start-up a company there is a really nice point, where you are successful, busy and things go pretty well. Then, things get busier, and then busier... well, and just a little more busier - so, I am getting back into this blog for 2010 and this year maybe a little more focus on the marketing or business side of things. Don't want to be too, too technical now, do we?

As you can imagine building a global "marketing" footprint can be a long and hefty task. To combine this with building an effective enthused ecosystem  can make the task seem like eating an elephant. For me and ChangeBASE the first couple of months of 2010 has seen an incredible demand from channel partners in the US and Europe..

Our relationship with Microsoft has enabled us to reach out and educate a vast number of potential partners. Last Thursday was testimony to this fact. Microsoft invited us to be their guest speaker to over 50 US Microsoft ACF and MDOP partners.

During the session we reviewed the challenges facing organisations of every size when migrating to a new OS and packaging their applications for effective deployment. We walked through the ChangeBASE AOK offering and discussed the benefits for an organisation using our technology to effectively plan their application migration and most importantly for the channel community we discussed how they can differentiate themselves from the competition with AOK, increase revenue and gain new customers. The result – within 24 hours of the call we had over 5 separate partners contact us, looking to sign partnership agreements and register business opportunities.

How did we achieve this? One could argue the might of the AOK offering. I believe it was 50% our market leading technology which saves organisations hundreds of thousands of pounds/dollars in migration and application packaging costs and 50% our close working relationship with the right people in Microsoft and their belief in our technology.

Lessons learned: to eat the elephant you need to have the right instruments (technology), the appetite (an enthused proactive channel) and the right connections (relationships).

That said, I just might be making things even busier for me... 


Monday, 1 March 2010

Windows HLP files: Still Bad

I often get asked about why Microsoft removed support for Windows Help (HLP) files under Windows Vista and Windows 7.  I mean how bad can some application documentation be right?

Well, it's not the content, it's the format. The WINHELP.EXE engine formats the HLP documentation files into a early form of HTML that can load some forms of executable content. This feature makes this file format particularly prone to a large number of security exploits.

To add some weight to this argument, Microsoft has added a security warning for a recent security vulnerability involving WINHLP (HLP) files which can be found here:

http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx

Specifically, the issue raised by the Microsoft security team is;
"The issue in question involves the use of VBScript and Windows Help files in Internet Explorer. Windows Help files are included in a long list of what we refer to as “unsafe file types”. These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system"
To find out more about these Microsoft executable file formats,  you may want to read the following Microsoft White paper found here:

Understanding Executable Content in Microsoft Products:
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=b7d03027-9791-443b-8bbe-0542b3aa4bfe

Thursday, 11 February 2010

Patch Tuesday: February 2010

With this February Microsoft Patch Tuesday Security Update, we see a significant security update with thirteen patches. Five patches were rated as critical, nine updates were rated as Important and one patch was rated as Moderate. Also worth noting, all patches released this month will most likely require a reboot of the target system.
In addition, the ChangeBASE AOK Patch Impact team has updated the sample application database to now more than 2000 unique application packages. All of the applications in this large sample application portfolio are analysed for application level conflicts with Microsoft Security Updates and potential dependencies, or down-level conflicts.
Based on the results of our AOK Application Compatibility Lab only one patch will have a moderate impact on a standard application portfolio; MS10-003 Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution. We have included a brief snap-shot of some of the results from our AOK Software that demonstrates some of the potential impacts on the OSP application package with the following snap-shot image.

MS10-003 Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution



Testing Summary
  • MS10-003 : "Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214)"
  • MS10-004 : "Vulnerability in Microsoft Paint Could Allow Remote Code Execution (978706)"
  • MS10-005 : "Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)"
  • MS10-006 : "Vulnerabilities in SMB Client Could Allow Remote Code Execution (978251)"
  • MS10-007 : "Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)"
  • MS10-008 : "Cumulative Security Update of ActiveX Kill Bits (978262)"
  • MS10-009 : "Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (974145)"
  • MS10-010 : "Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service (977894)"
  • MS10-011 : "Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)"
  • MS10-012 : "Vulnerabilities in SMB Server Could Allow Remote Code Execution (971468)"
  • MS10-013 : "Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)"
  • MS10-014 : "Vulnerability in Kerberos Could Allow Denial of Service (977290)"
  • MS10-015 : "Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)"


Patch NameTotal
Issues
Matches
Affected
RebootRatingRAG
Microsoft Security Bulletin MS10-003312%YESModerate impact and negligible testing profileYellow
Microsoft Security Bulletin MS10-004231%YESMarginal impact and negligible testing profileYellow
Microsoft Security Bulletin MS10-005<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-006<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-007<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-008<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-009<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-010<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-011<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-012<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-013<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-014<1%<1%YESMarginal impact and negligible testing profileGreen
Microsoft Security Bulletin MS10-015<1%<1%YESMarginal impact and negligible testing profileGreen

Legend:
No IssueNo Issues Detected
FixablePotentially fixable application Impact
SeriousSerious Compatibility Issue

Security Update Detailed Summary
MS10-003Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Payloadietag.dll, Mso.dll
ImpactImportant – Remote Code Execution

MS10-004Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution
DescriptionThis security update resolves six privately reported vulnerabilities in Microsoft Office PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadPowerpnt.exe, Pp7x32.dll, Pptview.exe
ImpactImportant – Remote Code Execution

MS10-005Vulnerability in Microsoft Paint Could Allow Remote Code Execution
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Paint. The vulnerability could allow remote code execution if a user viewed a specially crafted JPEG image file using Microsoft Paint. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadMspaint.exe
ImpactModerate – Remote Code Execution

MS10-006Vulnerabilities in SMB Client Could Allow Remote Code Execution
DescriptionThis security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit these vulnerabilities, an attacker must convince the user to initiate an SMB connection to a malicious SMB server.
PayloadMrxsmb.sys, Rdbss.sys, Sp3res.dll
ImpactCritical - Remote Code Execution

MS10-007Vulnerability in Windows Shell Handler Could Allow Remote Code Execution
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not impacted by this security update. The vulnerability could allow remote code execution if an application, such as a Web browser, passes specially crafted data to the ShellExecute API function through the Windows Shell Handler.
PayloadShlwapi.dll
ImpactCritical - Remote Code Execution

MS10-008Cumulative Security Update of ActiveX Kill Bits
DescriptionThis security update addresses a privately reported vulnerability for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000 and Windows XP, Important for all supported editions of Windows Vista and Windows 7, Moderate for all supported editions of Windows Server 2003, and Low for all supported editions of Windows Server 2008 and Windows Server 2008 R2. The vulnerability could allow remote code execution if a user views a specially crafted Web page that instantiates an ActiveX control with Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.
PayloadRegistry Keys Only
ImpactCritical - Remote Code Execution

MS10-009Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution
DescriptionThis security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if specially crafted packets are sent to a computer with IPv6 enabled. An attacker could try to exploit the vulnerability by creating specially crafted ICMPv6 packets and sending the packets to a system with IPv6 enabled. This vulnerability may only be exploited if the attacker is on-link.
PayloadTcpipreg.sys, Tcpipreg.sys, Netio.sys, Netio.sys, Netio.sys, Bfe.dll, Fwpkclnt.sys, Fwpuclnt.dll, Ikeext.dll, Wfp.mof, Wfp.tmf, Bfe.dll, Fwpkclnt.sys, Fwpuclnt.dll, Ikeext.dll, Wfp.mof, Wfp.tmf, Tcpip.sys, Tcpip.sys, Tcpip.sys, Tcpip.sys, Netiomig.dll, Netiougc.exe, Tcpip.sys, Tcpipcfg.dll, Netiomig.dll, Netiougc.exe, Tcpip.sys, Tcpipcfg.dll
ImpactCritical - Remote Code Execution

MS10-010Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service
DescriptionThis security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.
PayloadVid.sys
ImpactImportant – Denial of Service

MS10-011Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not affected. The vulnerability could allow elevation of privilege if an attacker logs on to the system and starts a specially crafted application designed to continue running after the attacker logs out. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.
PayloadCsrsrv.dll
ImpactImportant – Elevation of Privilege

MS10-012Vulnerabilities in SMB Server Could Allow Remote Code Execution
DescriptionThis security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.
PayloadSrv.sys
ImpactImportant – Remote Code Execution

MS10-013Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution
DescriptionThis security update resolves a privately reported vulnerability in Microsoft DirectShow. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadAvifil32.dll, Mciavi32.dll, Msrle32.dll, Msvidc32.dll, Tsbyuv.dll
ImpactCritical – Remote Code Execution

MS10-014Vulnerability in Kerberos Could Allow Denial of Service
DescriptionThis security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow a denial of service if a specially crafted ticket renewal request is sent to the Windows Kerberos domain from an authenticated user on a trusted non-Windows Kerberos realm. The denial of service could persist until the domain controller is restarted.
PayloadKdcsvc.dll
ImpactImportant – Denial of Service

MS10-015Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)
DescriptionThis security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on to the system and then ran a specially crafted application. To exploit either vulnerability, an attacker must have valid logon credentials and be able to log on locally. The vulnerabilities could not be exploited remotely or by anonymous users.
PayloadMup.sys, Ntkrnlmp.exe, Ntkrnlpa.exe, Ntkrpamp.exe, Ntoskrnl.exe
ImpactImportant – Elevation of Privilege


*All results are based on an AOK Application Compatibility Lab’s test portfolio of over 1,000 applications.

Saturday, 23 January 2010

IE6: Almost Negligence

Last year I had the opportunity to meet with one of the directors from Microsoft and he made some interesting comments which made me rethink my view of history a little.

One of the things that he mentioned was that the release of Windows XP SP2 (and it's associated security features) was a really a moral obligation by Microsoft to increase the security and protection for their massive Windows client base.  Windows XP SP1 was a nightmare for people connecting to the internet/web as it just did not have the correct security settings and features for people to surf online safely. Windows XP Service Pack 2 (XPSP2) included these necessary features and was released free of charge by Microsoft. Which was good news!

Whether this was a pragmatic realization that if Microsoft didn't do something quick to stem the flow attacks and vulnerabilities that Windows XP Service Pack (XP SP1) suffered they would be subject to a massive class-action legal suit or a true understanding of client requirements. Given the discussions I had with other people close to the development of XP SP2, I think it was the latter and a tacit acknowledgement of the responsibility Microsoft incurred when releasing Windows XP just prior to the rise the web and subsequent cyber-attacks.

I feel that we are in a similar position now with IE6. And this time, Microsoft is not in the moral hot-seat.

It is the now the IT directors who are maintaining Windows XP clients with Internet Explorer 6 (IE6). Internet Explorer 8 (IE8) has been released for a while now and with the recent, coordinated and sophisticated attacks used to hack into Google largely mitigated by IE8 and IE7, the further use of IE6 is getting into the arena of negligence.

I recognize that upgrades are time consuming, expensive and may require resources that could be used elsewhere. However, the savings of the continued use of IE6 may soon be far out-weighed by the costs of a successful attack on the corporate network.

Internet Explorer 8 and it's contemporaries (Chrome, Firefox) are now readily available , with much improved security and protections against internet attacks. It's time for these large (and mid-sized organizations) to get the planning and migration effort started - lest those high-backed leather executive styled chairs become uncomfortably warm.