Re: MS04-011 Break SSL support in IE 6.0.3790.0 with Windows 2003

From: Thor Larholm (thor_at_PIVX.COM)
Date: 04/17/04

  • Next message: Tiago Halm: "[BUG-CORRECTION] IISShield "Server" header costumization"
    Date:         Fri, 16 Apr 2004 15:34:05 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    This is a functionality regression that has been around for some time.
    The weird part of the MS04-011 patch is that it only occurs on Windows
    2003.

    KB261328: Cipher Strength Appears as 0-Bit in Internet Explorer
    http://support.microsoft.com/?kbid=261328

    SYMPTOMS
    In Microsoft Internet Explorer, you may experience the following
    behaviors:
    When you click About Internet Explorer on the Help menu, the Cipher
    Strength value is 0-bit.

    -and-
    You cannot connect to and view Web pages on secure Web sites.

    CAUSE
    This behavior can occur if the Schannel.dll, Rsabase.dll, or Rsaenh.dll
    files are missing, damaged, or of the incorrect version.

    Regards

    Thor Larholm
    Senior Security Researcher
    PivX Solutions
    24 Corporate Plaza #180
    Newport Beach, CA 92660
    http://www.pivx.com
    thor@pivx.com
    Phone: +1 (949) 231-8496
    PGP: 0x5A276569
    6BB1 B77F CB62 0D3D 5A82 C65D E1A4 157C 5A27 6569

    PivX defines "Proactive Threat Mitigation". Get a FREE Beta Version of
    Qwik-Fix
    <http://www.qwik-fix.net>

    -----Original Message-----
    From: Technoboy [mailto:technoboy@packetswar.org]
    Sent: Friday, April 16, 2004 11:04 AM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] MS04-011 Break SSL support in IE 6.0.3790.0
    with Windows 2003

    Hello everyone,

    A warning to all Windows 2003 user, this happened on two machine who had
    the exact same software configuration but different hardware.

    After installing the latest set of patches from microsoft, I was unable
    to access sites using SSL, after some investigation it turned out that
    my IE Cipher strength was set to 0bit ... After lot of troubleshooting
    and tryout with the different solutions offered by Microsoft I decided
    to take a guess and uninstall the MS04-011 patch... Well, the problem
    solved itself, the IE Cipher Strength is now at 128 like it was before,
    I can now access sites using SSL, windowsupdate, msn, etc

    Weird ...

    Anyone experienced something similar, or its just me ?

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    -----
    Earn up to 10 credit course hours toward the TruSecure ICSA Practitioner (TICSA) Credential and receive a TICSA exam coupon by attending the Infosecurity Canada 2004 conference. Featured speaker, Marcus J. Ranum, TruSecure inventor of the proxy firewall will present on June 3 at 11:30 AM. Visit <https://ticsa.trusecure.com> for certification details and <http://www.infosecuritycanada.com> for conference information. Become TICSA certified and see what happens!
    -----


  • Next message: Tiago Halm: "[BUG-CORRECTION] IISShield "Server" header costumization"

    Relevant Pages

    • Re: Virus in microsoft Patch
      ... "Windows must restart because the Remote Procedure Call ... your system and install the patch mentioned above. ... You can also configure Automatic Updates to automatically ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Is running a patch that changes something in Windows XP permis
      ... again for a Microsoft MVP: I have been trying to understand what the ... Windows XP versions before SP2 the system was recognised as SP2 RC1. ... > some things to quote here that tell us that the patch probably does not ... > change the value of TcpNumConnections in the registry and that there isn't ...
      (microsoft.public.windowsxp.general)
    • Re: Daylight Savings Time 2007 and Windows 2000 Server...
      ... Joe Richards Microsoft MVP Windows Server Directory Services ... support older versions of their software as well as Microsoft. ... patch for this problem but to also thoroughly test it and develop the ...
      (microsoft.public.windows.server.active_directory)
    • Re: CONFIG_VFAT_FS_DUALNAMES regressions
      ... The patch only changes the values stored for new files created by ... A filesystem is intact when all of its metadata is intact. ... in a virtual machine I connected it to the windows update service to ... see if there had been updates to the old install images I had, ...
      (Linux-Kernel)
    • RE: MS04-011 Break SSL support in IE 6.0.3790.0 with Windows 2003
      ... The weird part of the MS04-011 patch is that it only occurs on Windows ... MS04-011 Break SSL support in IE 6.0.3790.0 ... I can now access sites using SSL, windowsupdate, msn, etc ...
      (Bugtraq)