[Full-Disclosure] "windows update activex"

From: Liu Die Yu (liudieyuinchina_at_yahoo.com.cn)
Date: 07/21/03

  • Next message: Liu Die Yu: "[Full-Disclosure] remove HTML protections."
    To: full-disclosure mailing list <full-disclosure@lists.netsys.com>
    Date: Mon, 21 Jul 2003 12:08:35 +0800 (CST)
    
    

    >if there is some XSS hole in
    > Windows Update site or if there is a bug in IE that
    > allows to trick the URL,

    then the attacker can use Windows Update ActiveX to:
    reboot your machine;
    get detailed information on computer - computer name,
    hardware, isAdmin, etc.

    BUT it's hard for the attacker to execute his EXE.
    i've traced into the module("IUENGINE.TEXT").

    they first create the
    directory(API:"CreateDirectoryW")
    then they download the EXE file to the newly created
    directory. soon after that, they verify its digest
    (API:"LSTRCMPIW"). at last they verify it with
    "WinTrust.TEXT" - which i am unable to bypass. if any
    of the check fails, they delete the
    file(API:"DeleteFileW").

    assuming we already got WINDOWSUPDATE.MICROSOFT.COM(
    then we easily got MYCOMPUTER):

    the only chance is:
    "DeleteFileW" fails.

    but chances are very very slim.

    so generally speaking(generally speaking, we can't
    break WinTrust), the maximum risk is "RebootMachine" -
    nothing more.

    just as a reminder

    best wishes

    die

    -----------------------
    umbrella.mx.tc - http://umbrella.mx.tc
    safecenter - http://www.safecenter.net
    make notes easily - http://domex.int.tc

    _________________________________________________________
    Do You Yahoo!?
    国内电邮用户反垃圾调查拉开帷幕
    http://cn.rd.yahoo.com/mail_cn/tag/?http://cn.tech.yahoo.com/zhuanti/laji/index.html
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Liu Die Yu: "[Full-Disclosure] remove HTML protections."

    Relevant Pages

    • RE: Windows Update Error 80240030 -Now you see it, Now you dont
      ... whether or not it does the solution method below in order and can evade ... the Windows Update is done. ... the system construction utility, verify another solution method. ... related to proxy of the Internet Explorer. ...
      (microsoft.public.windowsupdate)
    • Re: Error?
      ... Click the Log On tab, and then verify that the service is enabled in every ... profiles, click the hardware profile, click Enable, and then click Apply. ... then perhaps reinstall the Background Intelligent Transfer ... You receive a "Windows Update has encountered an error and cannot display the ...
      (microsoft.public.windowsupdate)
    • Re: Download Fails
      ... When all else fails, HijackThis v1.99.1 ... Windows Update Checklist: ... But when I go to download them it brings up the ...
      (microsoft.public.windowsupdate)
    • Re: helpp
      ... Click the Log On tab, and then verify that the service is enabled in every ... profiles, click the hardware profile, click Enable, and then click Apply. ... then perhaps reinstall the Background Intelligent Transfer ... You receive a "Windows Update has encountered an error and cannot display the ...
      (microsoft.public.windowsupdate)
    • Re: carnt intstall windows update. get error code.
      ... Click the Log On tab, and then verify that the service is enabled in every ... profiles, click the hardware profile, click Enable, and then click Apply. ... then perhaps reinstall the Background Intelligent Transfer ... You receive a "Windows Update has encountered an error and cannot display the ...
      (microsoft.public.windowsupdate)

    Loading