Cache Disclosure Leads to MYCOMPUTER Zone and Remote Compromise

From: Liu Die Yu (liudieyuinchina_at_yahoo.com.cn)
Date: 11/25/03

  • Next message: OpenPKG: "[OpenPKG-SA-2003.049] OpenPKG Security Advisory (zebra)"
    Date: 25 Nov 2003 10:09:55 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Cache Disclosure Leads to MYCOMPUTER Zone and Remote Compromise

    [tested]
    OS:WinXp, CN version
    Microsoft Internet Explorer v6.Sp1; up-to-date on 2003/11/16

    [overview]
    By combining cache file disclosure and several other unpatched vulnerabilties, an malicious INTERNET page can reach MYCOMPUTER zone. The demo uses Adodb.Stream to launch a remote compromise attack.

    [demo]
    There are two harmless demos:
    Online demo, powered by ASP:
    http://www.safecenter.net/UMBRELLAWEBV4/LocalZoneInCache/LocalZoneInCache-Demo/index.html
    (runs harmless demonstration executable)

    [technical details]
    First, place an HTML file in IE cache directory and get its location.
    (Liu Die Yu's http://www.safecenter.net/UMBRELLAWEBV4/threadid10008/index.html)
    Second, this HTML file can be parsed as an HTML page and treated as in MYCOMPUTER security zone.
    (Mindwarper of mlsecurity.com's http://www.mlsecurity.com/ie/ie.htm)
    (Liu Die Yu's http://www.safecenter.net/UMBRELLAWEBV4/DblSlashForCache/DblSlashForCache-Content.htm)
    At last, Overwrite NOTEPAD.EXE and make IE launch it by openning a view-source protocol URL:
    (HTTP-EQUIV of MALWARE 's http://www.securityfocus.com/archive/1/343521)

    [Workaround]
    Disable Active Scripting in INTERNET zone, so HTML page opened in the cache can't send information back to the attacker.

    [Greetings]
    greetings to:
    Drew Copley, dror, guninski, vadim and mkill.

    -----
    all mentioned resources can always be found at UMBRELLA.MX.TC

    [people]
    LiuDieyuinchina [N0-@-Sp2m] yahoo.com.cn
    UMBRELLA.MX.TC ==> How to contact "Liu Die Yu"

    [Employment]
    I would like to work professionally as a security researcher/bug finder.

    See my resume at my site. I am very eager to work, flexible, and
    extremely productive. I have a top notch resume, with credentials
    from leading bug finders. I am willing to work per contract, relocate,
    or telecommute.
     
    [Give a Hand]
    I haven't got a job as a security researcher yet and my family don't support my security work - so, I don't have a computer of my own. Please consider about donating at:
    http://clik.to/donatepc


  • Next message: OpenPKG: "[OpenPKG-SA-2003.049] OpenPKG Security Advisory (zebra)"

    Relevant Pages

    • RE: OWA Errors
      ... THNAK YOU Jenny - it works and everything is fixed now. ... > C Restart IE and then access the OWA site again. ... Open an Internet Explorer window. ... > force the cache object to be updated. ...
      (microsoft.public.windows.server.sbs)
    • Re: HttpWebRequest problem
      ... It estabishes the connection to the server every time. ... The problem is that the> HttpWebRequest object internally uses the browser cache. ... > If I open internet explorer, enter the same URL and hit refresh couple> of times, the new version of the text file appears. ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: Spyware in Content.IES
      ... You ever see what kind of crap is in the "cache"? ... Temporary Internet Files Use More Disk Space Than Specified ... >>> MS uses a percentage of the hard disk for the cache. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: MS Windows 2003 SBS SP1 w/ ISA Server 2000 - Issues publishing a WSS site via ISA Server 200
      ... attempting to access the site from an external network (i.e. the Internet), ... On the SBS 2003 Server open the Server Management console. ... client computer, clear DNS, IIS and ISA cache on SBS and check if the ...
      (microsoft.public.windows.server.sbs)
    • Re: Spyware in Content.IES
      ... Internet files tend to be small, that means there are 10's of thousands of files in the ... The whole idea of the cache is to speed up access on slow internet connections by ... Dave ... |> MS uses a percentage of the hard disk for the cache. ...
      (microsoft.public.windowsxp.security_admin)