Re: [Full-Disclosure] RE: BAD NEWS: Microsoft Security Bulletin MS03-032

From: Dimitri Limanovski (dlimanov_at_sct.com)
Date: 09/10/03

  • Next message: Noel, Marcus: "[Full-Disclosure] Microsoft Security Bulletin MS03-039"
    To: Nathan Wallwork <owen@pungent.org>
    Date: Wed, 10 Sep 2003 10:43:45 -0400
    
    

    I agree that firewall is not the place to catch this. Any properly
    configured HIPS should be able to catch this or nay other
    similar-configured exploit without any issues though.
    We have OKENA and simple rule to prohibit (or prompt) program
    executions from within IE has stopped this (and dozen of others)
    exploit from working. FWIW, McAfee caught it as well, identifying it
    as Exploit-CodeBase but I'm sure this can be easily bypassed with
    little coding.
    Thanks,

    Dimitri

    |---------+-------------------------------------->
    | | Nathan Wallwork |
    | | <owen@pungent.org> |
    | | Sent by: |
    | | full-disclosure-admin@lists|
    | | .netsys.com |
    | | |
    | | |
    | | 09/09/2003 04:17 PM |
    | | |
    |---------+-------------------------------------->
    >--------------------------------------------------------------------------------------------------------------|
      | |
      | To: Drew Copley <dcopley@eeye.com> |
      | cc: ADBecker@chmortgage.com, "'GreyMagic Software'" <security@greymagic.com>, "'Bugtraq'" |
      | <bugtraq@securityfocus.com>, <full-disclosure@lists.netsys.com>, <http-equiv@excite.com>, |
      | "'NTBugtraq'" <NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM>, "'Microsoft Security Response Center'" |
      | <secure@microsoft.com>, <vulnwatch@vulnwatch.org> |
      | Subject: [Full-Disclosure] RE: BAD NEWS: Microsoft Security Bulletin MS03-032 |
    >--------------------------------------------------------------------------------------------------------------|

    On Mon, 8 Sep 2003, Drew Copley wrote:
    > The only sure way to detect this, I already wrote about [to
    Bugtraq]. That
    > is by setting a firewall rule which blocks the dangerous mimetype
    string
    > [Content-Type: application/hta]. Everything else in the exploit can
    change.

    Just so we are clear, the firewall wouldn't tbe he right place to
    catch
    this because that string could be split by packet fragmentation, so
    you'd
    need to look for it at an application level, after the data stream
    has been reassembled.

    Of course, if anyone thinks it is easier to protect their browser with
    a
    proxy than fix the browser they've got other issues.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Noel, Marcus: "[Full-Disclosure] Microsoft Security Bulletin MS03-039"

    Relevant Pages

    • Re: XP Network Problem.....
      ... Then checked browstat and network neighborhood. ... pointing to the Lenovo as the machine blocking access. ... the Lenovo browser was the only browser available to the network, ... I tried reconfiguring the Firewall to permit ...
      (microsoft.public.windowsxp.network_web)
    • Re: Default Browsers
      ... Firewall as a problem. ... same default browser; one is now set at IE6 and the other is set at ... (viewing Network Neighborhood from), ... Do you have a URL for a web page that will let me download "Browstat.exe" by ...
      (microsoft.public.windowsxp.network_web)
    • Re: Recurrent question
      ... of course it's the fault of the "Personal Firewall" ... This works with any browser. ... It's POC code. ... It has nothing to do with a browser vulnerability. ...
      (comp.security.firewalls)
    • Re: XP Network Problem.....
      ... With eMachine tech support help I ... Center identified as a firewall. ... In your articles you comment that one should not "host" the browser in an XP ... Both seeing a computer (as a server in browstat status, and in Network ...
      (microsoft.public.windowsxp.network_web)
    • Re: XP Pro SP2 hides from network
      ... I have tried disabling the firewall, but that doesn't have any affect (in ... Master browser name is: C64 ... All of the systems list the same Master Browser and the same 2 ... > |> network and my symptoms are the same as the situation that started ...
      (microsoft.public.windowsxp.network_web)

  • Quantcast