Thursday, January 28, 2010

IE flaw to be exposed at Black Hat, probably not fixable

Here's just one more reason to stop using IE to browse the Internet. Once this flaw leaks out to the bad guys, anyone using IE will be vulnerable. Because it affects SMB, IMHO it may be difficult-to-impossible to fix without breaking Microsoft Windows networking.

Internet Explorer Flaw Reveals Web Surfers Hard Drive Contents | CyberInsecure.com
... The hole is difficult to close because the attack exploits an array of features IE users have come to rely on to make web application work seamlessly. Simply removing the features could neuter functions such as online file sharing and active scripting, underscoring the age-old tradeoff between a system’s functionality and its security.

Based on Medina’s characterization, it appears that fixing the weakness will require changes in a Windows network sharing technology known as SMB, or server message block, as well as the way Windows makes file caches available to a wide variety of applications.

“The things we are reporting are not bugs, they are features,” Medina said. “They are needed for many applications to work, so [Microsoft] can’t simply remove or truncate” them.

IE suffers from at least one other long-standing security bug that can enable attacks against people browsing websites that are otherwise safe to view. It can be exploited to introduce XSS, or cross-site scripting, exploits on webpages, allowing attackers to inject malicious content and code.

Tuesday, January 26, 2010

I thought Google's motto was "do no evil".

This certainly doesn't qualify.  I have been uninstalling the Google toolbar from all my systems for the past few months, and now I guess that was a Good Thing to do ...

Sunbelt Blog: Google Toolbar tracks searches after it’s disabled.
Ben Edelman, Harvard privacy researcher and guru has revisited the features of Google Toolbar and was appalled to discover that disabling it doesn’t really disable it. He is recommending that all users uninstall it.

In a long, thorough and well-written piece on his blog Edelman discusses how he monitored the Toolbar’s behavior with a network sniffer and documented the transmission of data back to Google (to toolbarqueries.google.com). Not only does it track a user’s Google searches, but it also phones home information about searches done in other search engines.

And, the privacy policy, he says, is ill-conceived.

“Notice that the Privacy Policy loads in an unusual window with no browser chrome – no Edit-Find option to let a user search for words of particular interest, no Edit-Select All and Edit-Copy option to let a user copy text to another program for further review, no Save or Print options to let a user preserve the file. Had Google used a standard browser window, all these features would have been available, but by designing this nonstandard window, Google creates all these limitations.”

This, of course, prevents a user from using an application like EULAlyzer that points out areas of concern in end user licensing agreements and privacy statements.

Update Wed 27 Jan 2010 06:49: Ars Technica reports that restarting the browser stops the behavior, and Google is fixing the problem anyway.
Google: Toolbar data persistence a bug, fix available
We asked Google for comment, and a spokesperson told us there's a simpler solution: quit and relaunch the browser. That apparently gets the software to reload its preferences, and will put a stop to the transmission of URL data.

"It affects those using Google Toolbar versions 6.3.911.1819 through 6.4.1311.42 in Internet Explorer," the spokesperson told Ars. "Once the user restarts the browser, the issue is no longer present. A fix that doesn't require a browser restart is now available on [our site] and in an automatic update to Google Toolbar that we are starting tomorrow." The rapid response—Edelmen's report is dated today—suggests that Google was already aware of the problem and had put the fix through Q&A.

Sunday, January 24, 2010

Upcoming Blackhat presentation: ""IE turns your personal computer into a public file server"

I don't know how much credence to put in this announcement, but Core Security is a legitimate company with a long history of doing good security research, and Blackhat is a legitimate conference. If this is true, anyone with sensitive data on their computers (bank accounts, credit card numbers, tax returns, and the like), should probably not use IE for the foreseeable future.

I don't use IE except for Windows Updates, but those of you who do should STRONGLY consider switching to Google Chrome or Mozilla Firefox. Chrome is possibly safer because it runs partially sandboxed from the OS but everything you do on the Internet is fed into Google's databases; Firefox is much safer than IE, especially when enhanced with NoScript and Adblock Plus but unless you run as a non-administrative user (as I do) it runs with administrative access to the system.  FWIW I use Firefox -- Google already knows too much about me ;-).

"IE turns your personal computer into a public file server" - dslreports.com
I dunno. We just get a patch for a major vulnerability in IE and breathe a sigh of relief only to learn about another nasty vulnerability in IE that will be demonstrated at the upcoming Black Hat Conference. Sigh.

Researchers at Core Security, one day after Microsoft patched IE, have announced another set of vulnerabilities in Internet Explorer that involve stringing several minor vulnerabilities together to enable a hacker to have complete access to all files on the user's computer. The user would need to be enticed to click on a malicious link first.

The vulnerability, along with proof of concept, will be demonstrated at the Black Hat conference which begins Feb 2 in Washington. Core Security states that they are working with Microsoft to try and find a way to mitigate the risk. Microsoft has declined to comment.

Core Security page
Blackhat Conference Announcement
Reuters story about this

Friday, January 22, 2010

Is it time to remove Real Player from your system?

When was the last time you used Real Player to view anything?  If you can't remember, don't patch, just uninstall it.  The free open-source player VLC media player will play Real media, so you don't need it any more.

US-CERT Current Activity: RealNetworks, Inc. Releases Updates to Address Vulnerabilities
added January 22, 2010 at 08:36 am

RealNetworks, Inc. has released updates to address multiple vulnerabilities in several versions of RealPlayer for Windows, Mac, and Linux and several versions of the Helix Player for Linux. These vulnerabilities may allow an attacker to execute arbitrary code.

US-CERT encourages users and administrators to review the RealNetworks, Inc. advisory and apply any necessary updates to help mitigate the risks.

Thursday, January 21, 2010

Microsoft releases emergency patch for IE

Microsoft today released a so-called "out of band" patch for Internet Explorer (all supported versions).  I will be testing this on my systems, but home users should go ahead and run Windows Update and make sure this is installed.  NOTE: just because you have Automatic Updates enabled doesn't mean they're working.  Last night I applied almost 100 Windows Updates to a system which had Windows Updates on full-automatic-mode, but some part of the WU system had gotten corrupted and it wasn't working.  I opened an email case with Microsoft

The Microsoft Security Response Center (MSRC) : Bulletin MS10-002 Released
Today we released Security Bulletin MS10-002 out-of-band to address vulnerabilities in Internet Explorer. All customers using currently supported versions of Windows and Internet Explorer should apply this update as soon as possible. Once applied, customers are protected against the known attacks that have been widely publicized. For customers using automatic updates, this update will automatically be applied once it is released.


Other stories about this with non-Microsoft commentary are here:

In a totally unrelated development, version 3.6 of Firefox was released today.  It is not a security patch, so there is no need to rush it into production use.  I will be testing it and will report back here next week.

Mozilla drops Firefox 3.6 with security goodies | Zero Day | ZDNet.com
Mozilla has released the latest iteration of its flagship Firefox browser with a few significant security goodies to keep malicious hacker at bay.

The update, which is being shipped via the browser’s automatic update mechanism, includes new features to patch third-party Firefox plug-ins and lock out rogue add-ons.

There are no security vulnerabilities being fixed with this Firefox 3.6 update.

Wednesday, January 20, 2010

Another Adobe problem, this time it's the Shockwave Player

News today of another Adobe problem, only this time it's the Shockwave Player.  This is different from the Flash Player.  If you have it, Adobe says to uninstall it, REBOOT, and then install the new one.  I say just uninstall it -- most likely you don't need it unless you play online games that require it.

Critical flaws haunt Adobe Shockwave Player | Zero Day | ZDNet.com
Adobe’s run on the patching treadmill continued this week with a “critical” update to fix a pair of code execution holes in its Shockwave Player.

The vulnerabilities affect Adobe Shockwave Player 11.5.2.602 and earlier versions, on the Windows and Mac operating systems.

According to an Adobe advisory, an attacker who successfully exploits the vulnerabilities could run malicious code on the affected system.

* This update resolves a buffer overflow vulnerability that could potentially lead to code execution (CVE-2009-4002).
* This update resolves multiple integer overflow vulnerabilities that could potentially lead to code execution (CVE-2009-4003).

Adobe recommends Shockwave Player users uninstall Shockwave version 11.5.2.602 and earlier on their systems, restart their systems, and install Shockwave version 11.5.6.606.

D-Link routers easily hacked

I don't use D-Link routers, I use a recycled computer turned into a router using IPCop, but if you have a D-Link router you should follow the links.

This is important because once a "bad guy" has control of your home router, he controls your internet traffic and can make you think you are at your bank's website when in fact you're at his copy of your bank's website.

D-Link issues fixes for router vulnerabilities
Router manufacturer D-Link Corp. today admitted that some of its routers have a vulnerability that could allow hackers access to a device's administrative settings. The Taipei, Taiwan-based form said that it has issued patches to fix the flaws.

According to a Jan. 9 blog post from SourceSec Security Research, some D-Link routers have an insecure implementation of the Home Network Administration Protocol (HNAP), which could allow an unauthorized person to change a router's settings.

SourceSec published a proof-of-concept software tool called HNAP0wn that would enable the hack -- a move that D-Link criticized.

... D-Link and SourceSec differed over which models were vulnerable. SourceSec wrote that it suspected that all D-Link routers made since 2006 with HNAP support were affected, but they said they had not tested all of them.

D-Link said the models affected are the DIR-855 (version A2), DIR-655 (versions A1 to A4) and DIR-635 (version B). Three discontinued models -- DIR-615 (versions B1, B2 and B3), DIR-635 (version A) and DI-634M (version B1) -- are also affected.

The company said new firmware updates are being made available across its Web sites.

NOTE: The link in the Computerworld story is bad, click the corrected link here.