[NT] Prevx Pro Multiple Vulnerabilities (File Protection Bypass, Command Bypass)
From: SecuriTeam (support_at_securiteam.com)
Date: 08/02/05
- Previous message: SecuriTeam: "[EXPL] Baby Web Server Command Validation (Exploit)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 2 Aug 2005 18:07:36 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Prevx Pro Multiple Vulnerabilities (File Protection Bypass, Command
Bypass)
------------------------------------------------------------------------
SUMMARY
" <http://www.prevx.com/> Prevx Pro utilizes the latest behavior based
intrusion prevention technology." By using memory mapping it is possible
to access the programs that PrevX protects. In addition, by sending
invalid information it is possible to tell PrevX to allow a malicious
program to penetrate the system.
DETAILS
Vulnerable Systems:
* Prevx Pro IPS 2005
File Protection Bypass:
PrevX by default protected many critical files of the system. However, the
protection can be bypassed by using memory mapping. For example, to edit
winnt/win.ini file, open the file and do mapviewoffile, and then edit the
file from the memory. PrevX does not protect files being edited from
memory mapping IO.
Command Bypass:
PrevX kernel driver and the user-space applications talking with each
other by using NtDeviceIoControlFile. However, it seems the driver doesn't
check whether or not the user-application is from PrevX or not. It is
possible to bypass the protection by pretending a user send an "allow"
command down to the kernel driver every time a warning message is popping
up.
ADDITIONAL INFORMATION
The information has been provided by <mailto:trihuynh@huynhsec.com> Tri
Huynh.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[EXPL] Baby Web Server Command Validation (Exploit)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NT] USB Lock Auto-Protect Locally Stored Password Recovery
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... The program also offers drag-and-drop
folder protection ... Due to the fact that the USB Lock uses a weak encryption algorithm
to ... 'USB Lock Auto-Protect v1.5 Local Password Encryption Weakness ... (Securiteam) - [NT] Comodo Bypassing Settings Protection Using Magic Pipe Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Comodo Bypassing Settings Protection
Using Magic Pipe Vulnerability ... Comodo Firewall Pro version 2.4.18.184 ... (Securiteam) - [NT] Microsoft Word Protection Bypass
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... protection without using
any special tools. ... The same checksum can be found within the original Word ...
10:30 UTC Microsoft notified to: secure@microsoft.com ... (Securiteam) - [NT] ISS BlackICE PC Protection Filelock Protection Bypass
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... ISS BlackICE PC Protection
Filelock Protection Bypass ... database of trusted applications or firewall configuration
are protected. ... (Securiteam) - [NT] Prevx Home Intrusion Prevention Features can be Disabled by Direct Service Table Restoration
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Prevx Home prevents malicious
code from modifying critical Windows ... registry keys by prompting the user for action
whenever such an attempt is ... Prevx Home's registry and buffer overflow protection feature
is ... (Securiteam)