RE: [Full-Disclosure] RE: MS04-011 Break SSL support in IE 6.0.3790.0 with Windows 2003

From: Technoboy (technoboy_at_packetswar.org)
Date: 04/17/04

  • Next message: Thomas Wana: "[Full-Disclosure] void.at - neon format string bugs"
    To: <full-disclosure@lists.netsys.com>
    Date: Fri, 16 Apr 2004 19:58:45 -0400
    
    

    <http://support.microsoft.com/?kbid=261328>

    None of these solutions will resolve the MS04-011 issue with win2003,
    Microsoft recommand to reinstall IE6... If your IE is current on security
    patches and you download the IE 6 SP1 executable (ie6setup.exe) you will
    receive the following error message when trying to install:

    "Setup has detected a newer version of internet explorer already installed
    on this system."
    "Setup cannot continue"

    I even gave a try with the following registry hack:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed
    Components\{89820200-ECBD-11cf-8B85-00AA005B4383\"IsInstalled"=dword:0000000
    1

    Edited to...

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed
    Components\{89820200-ECBD-11cf-8B85-00AA005B4383\"IsInstalled"=dword:0000000
    0

    Did a reboot, selected yes when asked to remove the IE settings and i
    received another error stating that a 'newer version of internet explorer
    6.0 have been detected on this machine'...

    >This behavior can occur if the Schannel.dll, Rsabase.dll, or Rsaenh.dll
    files are missing, damaged, or of the incorrect version.

    I believe this is specific to Windows ME.

    For the moment, I uninstalled the MS04-011 patch, waiting for an 'patch for
    the patch' from microsoft... If anyone find a workaround, I would like to
    know.

    good weekend to all,

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Thor Larholm
    Sent: Friday, April 16, 2004 6:34 PM
    To: Technoboy; full-disclosure@lists.netsys.com
    Cc: bugtraq@securityfocus.com; ntbugtraq@listserv.ntbugtraq.com
    Subject: [Full-Disclosure] RE: MS04-011 Break SSL support in IE 6.0.3790.0
    with Windows 2003

    This is a functionality regression that has been around for some time.
    The weird part of the MS04-011 patch is that it only occurs on Windows 2003.

    KB261328: Cipher Strength Appears as 0-Bit in Internet Explorer
    http://support.microsoft.com/?kbid=261328

    SYMPTOMS
    In Microsoft Internet Explorer, you may experience the following
    behaviors:
    When you click About Internet Explorer on the Help menu, the Cipher Strength
    value is 0-bit.

    -and-
    You cannot connect to and view Web pages on secure Web sites.

    CAUSE
    This behavior can occur if the Schannel.dll, Rsabase.dll, or Rsaenh.dll
    files are missing, damaged, or of the incorrect version.

    Regards

    Thor Larholm
    Senior Security Researcher
    PivX Solutions
    24 Corporate Plaza #180
    Newport Beach, CA 92660
    http://www.pivx.com
    thor@pivx.com
    Phone: +1 (949) 231-8496
    PGP: 0x5A276569
    6BB1 B77F CB62 0D3D 5A82 C65D E1A4 157C 5A27 6569

    PivX defines "Proactive Threat Mitigation". Get a FREE Beta Version of
    Qwik-Fix <http://www.qwik-fix.net>

    -----Original Message-----
    From: Technoboy [mailto:technoboy@packetswar.org]
    Sent: Friday, April 16, 2004 11:04 AM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] MS04-011 Break SSL support in IE 6.0.3790.0 with
    Windows 2003

    Hello everyone,

    A warning to all Windows 2003 user, this happened on two machine who had
    the exact same software configuration but different hardware.

    After installing the latest set of patches from microsoft, I was unable
    to access sites using SSL, after some investigation it turned out that
    my IE Cipher strength was set to 0bit ... After lot of troubleshooting
    and tryout with the different solutions offered by Microsoft I decided
    to take a guess and uninstall the MS04-011 patch... Well, the problem
    solved itself, the IE Cipher Strength is now at 128 like it was before,
    I can now access sites using SSL, windowsupdate, msn, etc

    Weird ...

    Anyone experienced something similar, or its just me ?

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Thomas Wana: "[Full-Disclosure] void.at - neon format string bugs"

    Relevant Pages

    • Re: Is running a patch that changes something in Windows XP permis
      ... again for a Microsoft MVP: I have been trying to understand what the ... Windows XP versions before SP2 the system was recognised as SP2 RC1. ... > some things to quote here that tell us that the patch probably does not ... > change the value of TcpNumConnections in the registry and that there isn't ...
      (microsoft.public.windowsxp.general)
    • RE: WMF Exploit Patch Released
      ... it isn't so much Microsoft saying you should upgrade for this ... Will there be a WMF patch for Windows 95 as well? ... > The Norwich University program offers unparalleled Infosec management ...
      (Security-Basics)
    • So Windows Update is a dog, now what?
      ... extension, that means that the soon-to-be-released Windows Update, ... How about someone getting serious about patch management over at ... In their explanation of the severity rating scheme, the Microsoft ... incredibly reliable mechanism for getting patches onto systems, ...
      (NT-Bugtraq)
    • Re: Daylight Savings Time 2007 and Windows 2000 Server...
      ... Joe Richards Microsoft MVP Windows Server Directory Services ... support older versions of their software as well as Microsoft. ... patch for this problem but to also thoroughly test it and develop the ...
      (microsoft.public.windows.server.active_directory)
    • Re: Daylight Savings Time 2007 and Windows 2000 Server...
      ... support older versions of their software as well as Microsoft. ... patch for this problem but to also thoroughly test it and develop the ... Windows 98? ...
      (microsoft.public.windows.server.active_directory)