[Full-Disclosure] RE: new internet explorer exploit (was new worm)

From: Castigliola, Angelo (ACastigliola_at_unumprovident.com)
Date: 04/01/04

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] Re: Bugfinder Being Indicted As Criminal ("Counterfeiter") in France"
    To: <full-disclosure@lists.netsys.com>, <bugtraq@securityfocus.com>
    Date: Thu, 1 Apr 2004 11:02:48 -0500
    
    
    

    >The known ingredient it uses is :
    >http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-08/1758.htm
    l
    >that has gone unpatched for over 5 months now

    XP service pack 2 Release candidate 1 patches this exploit.

    Angelo Castigliola III
    Operations Technical Analyst I
    UnumProvident IT Services
    207.575.3820
     

    -----Original Message-----
    From: Jelmer [mailto:jkuperus@planet.nl]
    Sent: Monday, March 29, 2004 9:36 AM
    To: full-disclosure@lists.netsys.com; bugtraq@securityfocus.com
    Subject: new internet explorer exploit (was new worm)

    The code used by this worm to exploit it's users at least partly is (i
    think) new , the vulnerability it abused has afaik not been published on
    eighter bugtraq or full-disclosure. possibly making it (one of?) the
    first
    worm to totally catch people offguard.

    It allows a mallicious person to take any action on an unsuspecting user
    who
    view's a specially prepared page's pc

    The known ingredient it uses is :
    http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-08/1758.html
    that has gone unpatched for over 5 months now

    The remainder of the exploit manages to confuse this same adodb.stream
    object enough to make it think it's being run from a local location

    You can protect yourself against it by running
    http://ip3e83566f.speed.planet.nl/hacked-by-chinese/fix.reg

    I attached sample code myself to illustrate the problem, because
    http-equiv's was messy :)
    This one should be more straightforward to use

    Instructions :

    1. unzip
    2. overwrite exploit.exe with the executable you wish to run, or leave
    it
    untoched if you want to see some nice texturemapped rotation
    3. upload the files to a webserver
    4. view exploit.htm

    Tested on winxp pro all patches

    for the lazy ones among you can also view a demonstration here :

    http://ip3e83566f.speed.planet.nl/security/newone/exploit.htm

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


    • application/x-pkcs7-signature attachment: smime.p7s

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] Re: Bugfinder Being Indicted As Criminal ("Counterfeiter") in France"

    Relevant Pages

    • Re: Patch confusion
      ... Service Pack are rollup of everything released prior to it. ... customers want point-fixes for issues and infrequent Service Pack rollups. ... Others only want cumulative security fixes augmented by infrequent Service ... happy, patches are what you see, and nothing is compulsory. ...
      (microsoft.public.inetserver.iis)
    • Re: Creating XP update cd
      ... updates since service pack 2 and burn them to a cd? ... You can even integrate those patches into your Windows XP ... How to use the Windows Update Catalog ... Creating an Integrated Installation ...
      (microsoft.public.windowsupdate)
    • Re: Microsoft Antispyware & NETBIOS Messenger
      ... When I reboot it is again AUTOMATIC. ... worse than a hole that you do see and thus monitor. ... You mention that you have all the patches which implies that you're using ... service pack two and it should be disabled automatically unless you, ...
      (microsoft.public.windowsxp.security_admin)
    • Re: New Computer - Need Service Packs on CD
      ... Service Pack 1, and I can't get my internet connection to work ... You can download and save all updates for later use - including service ... You can even integrate those patches into your Windows XP ... How to use the Windows Update Catalog ...
      (microsoft.public.windowsxp.newusers)
    • Re: Security Readiness Disk
      ... Windows XP Pro Gold is Windows XP as it was released 2 years ago, ... > has all the current service packs and patches. ... > screen with all the service pack and patches, ...
      (microsoft.public.security)