Re: Microsoft's GDI Detetection Tool faults

From: Gadi Evron (ge_at_linuxbox.org)
Date: 09/25/04

  • Next message: Jeremy Epstein: "RE: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes"
    Date: Sat, 25 Sep 2004 18:41:06 +0200
    To: John Bissell <monkey321_1@hotmail.com>
    
    

    > Everyone better start getting the good patch soon before the new Sasser worm begins to spread! It's only a matter of time...

    I have some things to say to you, and others. Then I will elaborate on
    _yet_another_ JPEG vulnerability.

    I'll reply in the following order:
    1. Patches are good.
    2. Doomsday worms.
    3. Media hype.
    4. *New* JPEG vulnerability.
        (Let's hype it!)

    Although installing patches and checking for new patches is sound
    advice, and although this vulnerability has potential for harm, I just
    don't get it.

    Why go around spreading fear of a "doomsday worm"? If a worm shows up,
    it will. The social engineering risk of this vulnerability is
    considerably higher/easier than that of others in the past. Yet, there
    were similar vulnerabilities that ended up not "working out" for the bad
    guys.

    Are "viruses" as a group going to employ this? Absolutely. I am positive
    of that fact.

    Is it going to be huge? It might, I just don't see any reason to commit
    to it. It might just as simply be forgotten by next month's MS security
    patch release.

    Picking out one security issue a month and hyping it is bad policy, and
    I wish security experts would stop playing along with the media on this.

    Unlike some other vulnerabilities, this one is relatively easy to cope
    with in a "virus scan". Although compressed and thus problematic, the
    JPEG format is very orderly and simple. Any tampered JPEG would be
    discovered from a distance if somebody just looked.

    AV and IDS tools detect it, and people download the patches. That's good
    enough and as good as anything we can do.

    Those who do not install, update and use an AV, or fail to install
    patches will fall, as they always do. But how is that different than
    with any other worm?

    Malware will appear that will use this, and in fact - a creation kit
    already appeared this Friday, but please.. please.. I beg of you (not
    you specifically) - stop the media hype of the situation.

    People should be aware of the risks, protect themselves and not believe
    everything they see online. Throwing populations into a fit over this
    worm or that may be profitable, but it sure as hell won't solve the main
    issues.
    That's all just wishful thinking, though.

    There was a second problem with JPEGs, discovered by Maik Morgenstern,
    AV-Test.org.
    They found a picture that was tampered to kill IE, different from the
    problem disclosed in MS04-028 and discovered a year ago (!!).

    (a year.. makes you wonder, did they wait to release SP2 and what else
    is waiting for us that miraculously doesn't effect SP2?).

    Unlike that vulnerability, this one works on SP2 but doesn't seem to be
    exploitable.

    According to AV-Test.org/de, this was found in-the-wild. I am not their
    spokesman, although I am rather enthusiastic about their work. I only
    wish to stress the point that there is life beyond the monthly media-pick.

            Gadi Evron.


  • Next message: Jeremy Epstein: "RE: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes"

    Relevant Pages

    • Nimda Worm Alert
      ... A new worm named W32/Nimda-A (known aliases are Nimda, Minda, Concept ... It utilizes multiple IIS ... Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability ...
      (Incidents)
    • Nimda Worm Alert
      ... A new worm named W32/Nimda-A (known aliases are Nimda, Minda, Concept ... It utilizes multiple IIS ... Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability ...
      (Focus-IDS)
    • CERT Advisory CA-2001-23
      ... We believe the worm will begin propagating again on ... susceptible to the vulnerability described in CA-2001-13 Buffer ... time required to infect all vulnerable IIS servers with this worm ... and egress filtering should be implemented at the network edge. ...
      (Cert)
    • Re: Ingers spam email claims
      ... Suppose I'm a worm and I have just found a vulnerable share on ... machines, and because machines become vulnerable within hours of the ... last microsoft vulnerability patch release, ... therefore my work email account has been rendered virtually useless ...
      (sci.archaeology)
    • An email from my ISP about Windows Messenger
      ... Rather than wait for the next Internet worm disaster to ... Messenger) service which enables full system compromise. ... The Messenger service vulnerability affects basically all ... * Remember the SQL Slammer worm and the havoc it wrecked? ...
      (microsoft.public.security)