Wednesday, February 1, 2006

Humor: Adages of the Internet

According to Wikipedia, adages are short, but memorable sayings, which hold some important fact of experience that is considered true by many people, or it has gained some credibility through its long use.

I was reading up on Moore's Law and started to think about all the weird Murphy's Law variants that my friends and I used in college. So, I started to dig. Wikipedia has a pretty good list going and I can only laugh when I read them.

Here are some of the better ones:

  • Murphy's Law - "If anything can go wrong, it will." - So true. I first heard about this law in college programming but by the end of college, it make so much sense (on many different levels)
  • Occam's Razor - "Given two equally predictive theories, choose the simpler." - Perfect example of not following this? Steve Gibson and the WMF exploit. Need I say more...
  • Hanlon's Razor - "Never attribute to malice that which can be adequately explained by stupidity. " - It is commonly said that people are the weakest security link, but why? Well this Jinx.com t-shirt says it all.
  • Parkinson's Law - "Work expands so as to fill the time available for its completion. " - Anyone that has ever worked in the corporate world, knows this is true. =)
  • Godwin's Law - "As an online discussion grows longer, the probability of a comparison involving Nazis or Hitler approaches one." - Anyone that has watched a security mailing list has seen this happen right in front of their eyes.
  • Amara's Law - "We tend to overestimate the effect of a technology in the short run and underestimate the effect in the long run. " - Happens all the time.

I am sure there are more floating around the internet today. Anyone have any to add??

Fyodor on Nmap 4.00

Great Fyodor interview over at SecurityFocus. He goes over several of the new features in detail. Very good read for those that love Nmap.

Former SoC student Zhao Lei is working on the second generation of OS detection, which will use many new tricks. Nmap 4.00 uses application heuristics along with TCP/IP fingerprinting. Cool improvement.

Tuesday, January 31, 2006

Microsoft Internet Explorer 7 Beta 2 Released

Internet Explorer 7 Pre-Release Beta 2 is open to the public. Come and get it.

It only works on Windows XP SP2 and some say it looks & feels alot like Firefox.

BetaNews.com has a write-up on the new public IE7.

Updated Security Tools - Ephedra Free

1) Nmap v4.0 was released over at Insecure.org today.

The changelog reports one change from v3.9999 -
  • Added the '?' command to the runtime interaction system. It prints a list of accepted commands. Thanks to Andrew Lutomirski (luto(a)myrealbox.com) for the patch.

2) The password cracker known by all as John the Ripper was updated to v1.7 recently. Claims of significant performance increases are along improvements in the changelog.

3) The brute-force login hacker, Hydra, was updated to v5.2 on Jan 27th. It includes fixes for the SSH2 module and a new "VMWare-Auth" module. That should be interesting to test.

4) Cain & Abel was updated to v2.8.4 on Jan 19th as well. New features include:

  • Rainbowcrack-Online client - The client has been developed in collaboration with Rainbowcrack-Online team. Cain can now interact with the outstanding power of this on-line cracking service based on RainbowTable technology. The service is not free and you need a valid account to use this feature, please check current rates on their site. The communication between Cain and the web site is SSL enabled to ensure privacy of transmitted information.
  • Oracle Password Cracker (Dictionary and Brute-Force Attacks).
  • Oracle Password Extractor via ODBC.
  • MySQL Password Extractor via ODBC.

Monday, January 30, 2006

OS X for Intel 10.4.4 Leaked

The news was released on the OSX86 Project today. I am not a Apple user but I believe 10.4.4 is the highest Intel OS X released to developers.

Of course, 10.4.5 was released to developers recently but it was for the PowerPC chip only, I believe. I could be wrong however.

Apple was smart to get the hacking geeks on their side...but it is a paradox box. Hacking geeks that want Apple on intel will get it...TPM or not.

Nmap 3.9999 - Runtime Interaction Feature

On Friday, I was asked to port scan a new server at work. Cool, portscans are always fun. I knew I had Nmap 3.95 on my laptop, but I jumped over to Insecure.org to make sure I still had the "latest and greatest"...well I didn't.

Checking out the changelog, I found a very cool feature introduced in 3.98 BETA1. It is called "Runtime Interaction". Yep, the name basically sums it up. This feature was created by Paul Tarjan as part of the Google Summer of Code. But initially, it only worked in the Linux/Unix version of Nmap 3.98 BETA1.

Well, Nmap 3.999 added runtime interaction support to the Windows port as well. Thanks to patches from Andrew Lutomirski and Gisle Vanem.

Then Nmap 3.9999 (that is four nines) was released. It added several minor nmap-protocols and mac-prefixes file updates over 3.999 (that is three nines).

Pretty cool. The runtime interaction feature should come in handy during large network scans. Anyways, update your ports or go directly to the source and get Nmap 3.9999

Friday, January 27, 2006

Microsoft Will Remove BlackWorm AFTER D-Day

The payload for the BlackWorm is set to activate on Feb 3rd but Microsoft isn't going to release their updated Windows Malicious Software Removal Tool until Feb 14th (Black Tuesday). Does that make any sense?

Sure, it really isn't Microsoft's job to clean worms off your computer - or is it?

Microsoft fully understands the worm at this point. They even wrote a full analysis of it. They call it a "Moderate" threat on their OneCare site as well.

Microsoft wants to make a move into the Anti-virus marketplace, right? Wouldn't this be a great chance to prove something to their possible customers?

Saving the data of thousands of people (perhaps tens of thousands) would be a good faith sign for a new comer in the AV world, would it not?

Microsoft cares about your security, seriously....as long as that caring can fall on the second Tuesday of the month (aka Black Tuesday).

Microsoft wants your money, they want your business but they can't release a tool a little early to save your data. However, normal people that just want to do good will spend all their free time protecting people they don't even know. In this case, that group was the BlackWorm Task Force.

Nice work Gadi and everyone that was involved in that underground effort.

Credit on the information dig goes to Fergie via the FunSec Mailing List.

Complacency – Still a Security Threat

You are the security administrator of a large data center. You have disabled all unnecessary services, triple-checked the firewall rules, conducted penetration tests on all active servers, written security procedures, and trained all employees on basic security ideas. You are golden right? Wrong.

One threat still remains – Complacency.

Complacency can be defined as the act of being content to a fault with one’s actions. In the information security world, it can be one of the hardest attack vectors to identify. Bleeding Snort does not have signatures on file to detect complacency and it will not show up in an event log report.

Complacency comes one from what some would call the weakest link in the security chain – people.

In simple terms, it is the difference in “doing everything you can to secure a network” and “thinking you already have”. Administrators aren’t perfect and therefore mistakes will be happen - c'est la vie. We are only human after all. But experts have warned about security complacency for years. However we never hear about the countermeasures.

I can only think of one – vigilance.

Always assume you have missed something, always watch for changes that were unexpected, stay on top of the news and emerging security threats, etc. Being vigilant should not control your every thought but it should be a layer in your thought process.

Recently, Bill Thompson over at BBC News cracked the hardened surface of this subject again in his “Mac user ‘too smug’ over security” article. He was quite surprised by the overall response of the Apple community.

Too many times, people feel they are more secure because they run _______. This is the red flag of complacency. This isn’t to say that people are wrong when they say “this operating system has a better security model (by design)” or “this operating system is more secure out of the box”. We all need to mindful no matter what OS we have on our machine.

It has always been my belief that a computer is only as secure as the person managing the box. Of course, all operating systems can be hardened beyond the default install. However, hardening servers should only be done by professionals that understand the workings of the system. If you don’t know what you are doing, you can easily harden yourself into an unscheduled DR situation. Anyone that works in the IT world knows managers don’t like unscheduled DR situations. =)

Moral of the Blog – Security is a very complex and fluid issue. Everyday, the security of a given system ebbs and flows as events on the internet unfold. Security isn’t filling in a checkbox on a requirement form or applying a single patch.

Staying vigilant is the only true countermeasure to security complacency.

Humor: Andy in Hyderabad, India

Most people know the pain of having computer problems, even IT professionals. We have all had those certain Tech Support calls that just didn't seem to really help. This great ConanO'Brien clip may give us insight into why this may happen.

Any goes to Hyderabad and causes trouble - (9MB Windows Media Vid)

Hyderabad is seen as the second "Silicon Valley" of India, after Bangalore. Hyderabad has several software technology campuses with leading companies such as Infosys, Microsoft, CSC, Oracle, Wipro, Kanbay, GE, iGate, ValueLabs, ADP, Dell, Deloitte, HSBC, SumTotal, Intergraph, Analog Devices, IBM, Keane, Baan, , Tata Consultancy Services, Amazon and Google having established centers in the city.

I love Wikipedia.

Thanks go to MW for the link.

TGIF

Thursday, January 26, 2006

Intel Macs - Get One Now or Wait?

Wired.com has a good article on just this subject.

Here are some of the reasons to wait:

1) "Most applications that run in OS X Tiger are able to run on Intel hardware via an emulation layer called Rosetta, but there are a few exceptions, spelled out in Apple's Universal Binary Programming Guidelines"

Also check out MacFixIt.com

2) "Jobs demoed Photoshop at Macworld, but conceded that the application's performance is worse under Rosetta than the speeds offered by older PowerPC hardware."

This is to be expected has that move to the Intel Chipset. Apps will be redesigned to take advantage of the Intel code, but that will take time.

3) "Almost every version of Windows requires a BIOS to launch, and Apple's Intel Macs use Intel's new extensible-firmware interface (EFI) instead, which Windows XP doesn't support. Vista supposedly will, so it might be possible by the end of the year."

Dual-Booting with Windows XP and OS X is not currently possible. But in a non-official way, this may be open to some hackers before the public. There is a contest running right now. First person to provide the steps and pictures will get a prize. That prize is currently over 7000 dollars and likely to go higher.

Tuesday, January 24, 2006

"Cleaning the Air" in Court (Fun)

I was reading the DailyDave mailing list this evening and found this little gem from Dave Aitel. After a quick Google search, I found this 2004 article over at SFGate.com

In February 2002, Consumer Reports published a lengthy article reviewing 16
different air purifiers. It placed the Ionic Breeze Quadra model at the bottom of its rankings, saying the device produced "no measurable reduction in airborne particles."

Consumer Reports ran a second article on purifiers in October 2003. Once
again, Ionic Breeze ended up near the bottom of the magazine's rankings.

Fun stuff. Not only does it not clean the air it produces high level of ozone.

In May 2005, Consumer Reports reported new finings that the Ionic Breeze Quadra S1737 SNX and four competing devices emitted excessive amounts of ozone that could cause respiratory difficulty when operated close to the user.

Wednesday, January 18, 2006

The Fight for Internet Neutrality Principles

Wikipedia defines Network Neutrality as the following:
Network neutrality is a principle of internet regulation with particular relevance to the regulation of broadband. It suggests that (1) to maximize human welfare, information networks ought be as neutral as possible between various uses or applications, and (2) if necessary, government ought to intervene to promote or preserve the neutrality of the network. Underlying the theory of the benefits of network neutrality is a belief that a neutral network promotes Schumpterian, or evolutionary innovation of information technology.

Sounds good eh? Well not everyone likes the sound of it.

BellSouth has talked about plans for a while to charge service providers extra for premium network usage. For example, Yahoo could pay BellSouth to make Yahoo Mail load up faster than Google Mail, or Microsoft could pay BellSouth to make MSN Search give results faster than Google Search - you get the idea.

Many in the IT world feel this new plan is direct more toward VoIP but who knows for sure and how really want to wait and find out. Opponents of this new plan as a power grab attempt by the major telephone companies, since most of them passed up the idea of the internet in the beginning.

Right now there is a piece of legislation at the U.S house of Representatives that connects directly with this "network neutrality" issue. Google believe this new legislation needs to be modified to protect the idea of neutrality for the internet.

Jeff Pulver, the man behind the company that is now called Vonage, even called for a Google and others to start a BellSouth Boycott yesterday.

Blogs and media sources have exploded in a new round of pay-for-QOS stories.
Silicon Valley.com Blog
Techdirt.com
MSNBC.com
CNNMoney.com

In response to this round of media noise, three consumer groups repeated today calls for a U.S law to prevent broadband providers from blocking or slowing customer access to some internet content by saying the public wants government protection.

"If we're not careful, we'll miss signs that there are threats to openness that makes the Internet so great," said Michael J. Copps, a Democrat on the U.S. Federal Communications Commission (FCC), speaking at the consumer groups' press conference. "The more concentrated that our [broadband] providers become, the more they have the ability, and possibly even the incentive, to act as Internet gatekeepers.

Google responded today with support for the neutrality principles in the NetworkingPipeline Blog.

Google's Barry Schnitt told Paul in an email: "Google is not discussing sharing of the costs of broadband networks with any carrier. We believe consumers are already paying to support broadband access to the Internet through subscription fees and, as a result, consumers should have the freedom to use this connection without limitations."

Tuesday, January 17, 2006

FSF Releases Draft of GPL v3

The Free Software Foundation (FSF) has released a draft of the GNU General Public License (GPL) Version 3.

One of the more interesting provision focuses on GPL software in DRM software. It prevents GPL-licensed software from being used in DRM copy-protection software.

"We are trying to do what we can, in a limited way, to use the freedoms that our licence gives us to actively work against the spread of DRM restrictions," said Eben Moglen, an FSF board member and one of the authors of the draft.

This provision was most likely set into stone after Sebastian Porst discovered LPGL code from the LAME project, mpglib and VideoLAN in the F4I code used in Sony's XCP software.

Monday, January 16, 2006

When Breakfast Shacks and Wifi Clash

Pretty cool story about how a small group of people found a connection between Starbucks new test ovens and their T-mobile wireless internet woes.

http://www.tmobiledoesntworkatstarbucks.org/

I have seen similar issues at my local starbucks, but it isn't every couple of mins.

New Security Tools - Now with Taurine!

Two updated tools were released on Sunday.

1) Paros Proxy 3.2.9 - Great tool to track Web Application traffic and check web application integrity. It allows the user to not only monitor and capture all HTTP & HTTPS data passing between severs and client, but it also allow users to track and modify cookies and form fields data on the fly.

2) Metasploit Framework v3.0 Alpha 2 - The Metasploit Framework (MSF) is an advanced open-source platform for developing, testing, and using exploit code. This project initially started off as a portable network game and has evolved into a powerful tool for penetration testing, exploit development, and vulnerability research. Remember this is a Alpha release and should only be used for testing purposes.

Ok, so I made up the Taurine part. While dietary taurine can be found in shellfish and organ meats like liver, I enjoy the primary taurine source of ubergeeks - Redbull.

Saturday, January 14, 2006

Open Source WMF Patch for Windows 98SE

As many of you know, Microsoft has decided not to release an official patch for the SetAbortProc() WMF flaw. Systems before Windows 2000 are not exploitable directly by default; therefore MS doesn’t see it as a critical security problem. It is also a great way for them to push users into upgrades however, but that is another issue all together. Lack of real security should be enough to force users into a move away from the Win9x kernel.

Microsoft has stated that they will only release really critical security patches for the Win9x platform until June 30 of this year.

But not everyone is happy about seeing this possible security risk before them. Open Source to the rescue. Inspired by Ilfak Guilfanov’s XP patch, Tom Walsh of the SecuriTeam blog has released his own open source WMF patch for Win9x Systems.

Nice work Tom.

Friday, January 13, 2006

The WMF Backdoor Debate

I don't believe the general press has grabbed on to this yet but there is a nice little debate happening right now on the security list. Was the WMF bug a deliberately designed backdoor into Windows?

Steve Gibson of GRC believes it might be and attempts to produce evidence on this Security Now Website.

I will let the reader decide on their own...but not everyone in the world agrees with Steve Gibson. I personally believe he may need to shave some off the top a bit. However we may never know the truth about why and how the WMF vuln was allowed to exist for so long.

Right now there is a great debate happening on Full-Disclosure and FunSec. Newer post are on the bottom.

Perhaps we can chalk it up to the today being Friday the 13th and a Full Moon.

Tuesday, January 10, 2006

Beware of Some "Antispyware"

Mark Russinovich has a great write-up on the new Antispyware Conspiracy. These so called "antispyware" products are pure danger and most of the times are far worse than the spyware they claim to find. This should be a good wake-up call to those users out there that fall for these types of tricks.

Stick to the popular and well-known products - Spysweeper, Counterspy, Ad-Aware, Microsoft Antispyware & SpyBot S&D.

Professionals also use more expert tools like HiJackThis. But due to damage that can be caused by this tools, only experienced people should go beyond the six stated above.

Dan Hubbard of Websense stated on the FunSec mailing list that they are tracking several of these fake antispyware programs at not just making you pay for nothing. Some are going a step beyond and planting keyloggers and traffic redirectors to steal credentials.

Patch Tuesday is Here

Here is what my computer just install - Windows XP SP2. This first one sounds pretty serious, going to keep eye on information connected to Kb908519

------------------------------
(KB908519) - MS06-002 - CVE-2006-0010

A vulnerability exists when viewing Embedded Web Fonts that could lead to remote code execution. Reported by eEye.

(KB902412) - MS06-003 - CVE-2006-0002

A vulnerability exists in TNEF messages that could allow remote code execution. Reported by John Heasman and Mark Litchfield of NGS Software.

The Spin Begins - Internet Explorer WMF DoS Vulnerability

Several days after the WMF DoS PoC was released, Lennart Wistrand @ Microsoft has responded on the MSRC blog.

"Lennart Wistrand here. I wanted to write a few lines about the public post made over the weekend about a new specially crafted WMF image that could potentially cause the application using the Windows Graphics Rendering Engine to crash. As it turns out, these crashes are not exploitable but are instead Windows performance issues that could cause some WMF applications to unexpectedly exit. These issues do not allow an attacker to run code or crash
the operating system. They may cause the WMF application to crash, in which case the user may restart the application and resume activity. We had previously identified these issues as part of our ongoing code maintenance and are evaluating them for inclusion in the next service pack for the affected products."

Wow. So now DoS is a performance issue. I rather Microsoft say "It isn't very dangerous yet, it isn't being exploited in the wild and we have more important issues to fix".

Important issues like:

EEYEB-20050505 - Remote Code Execution Vuln in IE and Outlook
EEYEB-20050627 - Remote Code Execution Vuln in Windows W2k-2003
EEYEB-20050801 - Remote Code Execution Vuln in Windows W2K-2003
EEYEB-20051017 - Remote Code Execution Vuln in IE and Media Player (metafile/media file??)

Let's not get into the DoS, Privilege Escalation, Security Bypass, System Access vulnerabilities listed for a wide range of Microsoft products on Secunia.

And those spoofing problems with IE that help phishers attack normal internet users.

Microsoft, you are doing better that is for sure, but the spin isn't needed. We are all adults here...

Monday, January 9, 2006

More WMF Woes for Microsoft - DOS Vulnerability - UPDATED

Symantec issued a vulnerability alert on its DeepSight Threat Management System that warns customers of multiple memory corruption vulnerabilities in the same rendering engine that Microsoft just patched (MS06-001).

As far as the information on the ground, it looks more like a DOS vulnerability at this point, but code execution should never be ruled out. Microsoft should remember this lesson from the IE flaw discovered by Benjamin Tobias in March of 2005. Once thought just to be a DoS vulnerability, it turns out that it also allows execution of arbitrary code.

Right now, it would appear that the DOS applies to Windows 98, 2000-2003 and Vista. Fine tuning of this information will occur over time however.

Moral to the story, no threat is too small to examine and take into account.

Reminds me of our ever changing road system.

At first, there are five pretty small potholes in the road. DOT comes out and fixes the biggest one, which most likely causes the most complaints and the biggest headaches. But after a while, those four other holes, grow and cause just as much problems if not more than the original.

UPDATE - It has been barely an hour from my original post. Andrey Bayora posted the following information on the FD Security Mailing list. I have no tested this WMF files at this point. Just passing the new information.

Well here is the PoC for the 2 new WMf vulnerabilities discovered by cocoruder and is not covered by MS06-001.

You can download WMF images at -http://www.securityelf.org/files/WMF-DoS.rar

UPDATE x 2 - It would seem that the first WMF flaw took Microsoft by surprise. Kevin Kean, a director in Microsoft Security Response Center (MSRC), said the following in this CNET article.

“"It is not a common buffer overflow," Kean said.”The software has a behavior that people can take advantage of. Obviously we did not intend it to be used in that way."

I was hoping Microsoft had learned that valuable lesson by now. Attackers and hackers use things all the time in a way they were not intended. This “Intending” issue is one of the core secure coding software problems.

Programmers always “intended” users to use correct data inputs and never “intend” to let the users input data over the limit of a buffer…but it happens. Part of the secure coding idea, is to look at your code and find the places were attackers could use the code in ways that were not “intended”.

On a positive node, this situation will remind Microsoft why it can not leave old code laying around. This new security push can only help in my mind. No pain, No gain.

Friday, January 6, 2006

Music DRM - Where are we now... UPDATED

Coldplay's new CD is loaded with DRM rules.

The CD has been manufactured for usage in regular CD players, but might not play in the following players:

  • Some CD players that have the capability of burning into an MP3 (such as portable players or car stereos)
  • Some CD players that posses CD-R/RW functions.
  • Blah, Blah, Blah.

Just look at the insert and you will quickly figure out that your freshly paid for CD will not play anything else a Generation 1 CD Player that has no other functions. Thank god for all these CD standards and new functions...right? Now we can't even listen to our music - which we just paid for.

Just so everyone knows, this huge list of stuff has done ZERO to stop internet trading. In this case, I saw the whole albums on BitTorrent sites almost 3 or 4 weeks before the CD was even released to stores.

So people can get it now or wait, pay and not be able to play it on their iPod, in their car or in their computer...umm...choices. =)

However in other more positive news, the EFF has sent an open letter to EMI records. In the letter published Wed, EFF urges EMI Music to publicly declare that it will not take legal action against computer security researchers who study copy-protected CDs released by record labels owned by EMI.

Basically the EFF believes that fans deserve to know whether EMI's copy-protected CDs are exposing their computers to security risks. After Sony attempted to sweep the whole XCP DRM rootkit story under the bed sheets, this sounds like a damn good idea - IMHO.

In late December, Sony BMG agreed settle to the class action over its XCP DRM rootkit. Mark Russinovich has a great blog about it as well.

One of the funny points in the agreement is that Sony BMG must provide the music on the CDs as unprotected MP3 files. Which is exactly the XCP DRM was created to stop. Ironic.

UPDATE - Paul Ferguson pointed me to a very interesting development in Sweden. A groups of students at the Viktoria Institude in Gothenburg has worked out a system of P2P music listening and sharing that runs on WiFi-enabled PDAs and allows users to actively recommend songs by pushing music to other users in the proximity. Wow.

Thursday, January 5, 2006

Official Microsoft Patch Released - MS06-001

http://www.microsoft.com/technet/security/bulletin/advance.mspx

"Microsoft announced that it would release a security update to help protect customers from exploitations of a vulnerability in the Windows Meta File (WMF) area of code in the Windows operating system on Tuesday, January 2, 2006, in response to malicious and criminal attacks on computer users that were discovered last week.

Microsoft will release the update today on Thursday, January 5, 2006, earlier than planned. "

Also, two other critical patches will be released in-band on Tuesday the 10th. Lets not forget about those and the chances that exploit could be created from those patches. If the holes are serious enough, that could be another whole problem in itself.

UPDATE - http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx - The patch is here.

Updated Microsoft Advisory for WMF

http://www.microsoft.com/technet/security/advisory/912840.mspx

The key changes are related to embedded WMF files via Office and the affected OS list. No real surprises here. They have basically just officially confirmed notes that you have seen on this blog and others.

1) Embedded WMF file in Office document are dangerous. This was known in the community.

2) Windows 9x & ME are less vulnerable to a direct OS Level attack by default, but if you are using third-party image viewers on these OSs, than it is possible you are vulnerable as well. Check with the vendor of your applications for the details.

WMF FAQ by HD Moore

The creator of the Metasploit Framework has released his own WMF FAQ. This was posted to the FD Security Mailing list this morning. Good information.

---------------------------------------------------

Q) Why did you release an IDS and AV evading exploit module so soon after the vulnerability was discovered?

A) The vulnerability was being exploited, in the wild, for at least two weeks (based on email reports) prior to the original BT post. The WMF structure is widely documented. The AV vendors were providing less-than-capable signatures for no reason other than that no public code was available that demonstrated alternate encodings. The IDS vendors were (and some still are) providing signatures that couldn't survive a single legal byte change in the WMF header. The release of a "polymorphic" (not) exploit forced the vendors to either fix their products or cry "irresponsibility" and give up. IPS vendors realized how SOL they are wrt to client-side HTTP attacks (so many encodings, so many ways to DoS an IPS that tries to decode them).

Q) The Windows Meta File format has a number of optional headers, can any of these be used to trigger the arbitrary code execution flaw via SetAbortProc?

A) No. The CLP headers (16 bit and 32 bit) cause the Picture and Fax Viewer (PFV) and Internet Explorer to throw an error when trying to render the image. Internet Explorer will only display an image internally if the "placeable" header has been prepend to the bare WMF header. If the "placeable" header exists, a device context check will fail during the call to Escape() and the SetAbortProc() function is not reached. This effectively prevents IE or the PFV from executing the SetAbortProc() call when any optional header has been prepended. This may not hold true for Explorer's preview and icon view.

Q) What about the Enhanced Meta File format? Does this format allow access to the exploitable function?

A) No. The EMF format has a separate API (which may or may not have its own problems), but it does not allow access to the WMF Escape() function. A WMF file can be delivered with the EMF extension however, which will cause it to be processed with the vulnerable API.

Q) Are there any other ways to obtain code execution besides via WMF files viewed by PFV or Explorer?

A) Yes. Any application that accepts WMF files and calls PlayMetaFile with the supplied data can be exploited. Some of these only recognize WMF files with the placeable header, which may prevent the application from reaching the SetAbortProc function. There are *many* other places where standard (ie. included with the OS) applications call the PlayMetaFile function, its just a matter of figuring out which ones can be used to deliver the malicious WMF content. A potential vector includes the display of icons stored inside of a standard executable. Viewing these files in an Explorer directory listing could result in the execution of code in an embedded WMF file. This has yet to be tested.

Q) What WMF header fields are mandatory for code execution through the PFV ?

A) Not many. The Windows Meta File header and possible field values are listed below:

# Possible values: 1 or 2 (memory or disk) WORD FileType

# The HeaderSize must always be 9
WORD HeaderSize;

# The Version field can be 0x0300 or 0x0100 WORD Version

# This parameter can be anywhere from 0x20 to 0xffffffff DWORD FileSize

# Completely arbitrary
WORD NumOfObjects

# Completely arbitrary
DWORD MaxRecordSize

# Completely arbitrary
WORD NumOfParams

The MSB of the actual MetaFileRecord function field is completely ignored.

Credits: A number of anonymous sources contributed to this information.

More information on the WMF structure can be found at the following sites:
- http://wvware.sourceforge.net/caolan/ora-wmf.html
- http://www.geocad.ru/new/site/Formats/Graphics/wmf/wmf.txt

-HD

Wednesday, January 4, 2006

Upcoming Sober Threat - Friday, Jan 6th

It is highly possible they will we see a new Sober variant this Friday.

The first Sober Worm appeared in October 2003, but now the word "Sober" has turned into a huge series of variants.

AV vendors don't use common names, so it is normally pretty hard for normal people to cross reference Sober variants. We are at Sober.Y, or is it Sober.AH? Who knows, just know that they are dangerous. =)

Algorithm-Based URL

Many of the sober variants contain a very complex algorithm that is used to compute the next series of download URLs.

LURHQ has a great write-up on the date algorithm.

You heard Jan5th right? So did I. But LURHQ reports that the branch logic points to Jan 6th.

"Note that the "begin update" logic in the current variant is actually "current date > Jan 5", not "current date == Jan 5", so the update other sources are saying will occur on Jan 5, 2006 won't actually happen until Jan 6, 2006. "

Keep your eyes open this friday for strange e-mails and keep your ears on all the AV news.

Advanced "Keep-alive" Tricks

Most Sober variants have been shown to deactivate many popular antivirus packages, including Microsoft AntiSpyware and HijackThis.

When it gets in, it is pretty hard to remove. Booting on a Linux disc and cleaning the infected disk sounds like a good idea however.

Mass-Mailing MO

Most Sober variants have their own SMTP engines and generate large amounts of e-mail traffic. Sober uses e-mail generation as a method to spread.

But how can e-mail spreading still be effective?? People have been told not to click on unknown links, don’t open e-mail from strange people…delete, delete.

Sober is the king of using Social Engineering (SE) attacks in mass e-mails however. Sober.X included real looking messages from the CIA, the FBI and the German Bundeskriminalamat (BKA).

An alleged child porn offender even turned himself in to the police after receiving one of these Sober e-mails.

History / Political Motivations

One Sober variant sent messages of support for the far-right groups in Germany pending the local elections in the state of North-Rhine Westphalia. Some groups see connections between Sober Key dates and important days in history. WW2, Battles in German, Nazi party, etc, etc.

Are these motivations true or just a smart SE attack? Who knows...and in the sense of security, I don’t care.

Summary

1) Watch your e-mail servers tomorrow. It is possible they we will see a huge flux of e-mails generated by this “Sober update code”.

2) Block the known update sites listed in this F-Secure blog entry.

3) Make sure you e-mail gateway AV is up-to-date and stays that way. Double check AV on your endpoints and make sure it is updating as well.

3) Remember the Sober creator (or group) aren’t stupid and most likely aren’t very poor either.

As that old NSA saying goes: “Attacks always get better, they never get worse.”

WMF - Six Days Til Checkered Flag

Information comes in as fast as Le Mans racers sometimes. Here is an update.

1) A pre-release "official" Microsoft patch was leaked from Redmond it would seems. People have tested it and it has caused many problems. BSOD, etc. So even if it is an "official" leak, it will break stuff. Don't mess with it.

2) The "patch" by Ilfak Guilfanov has been supported by many big groups (F-Secure, SANS, etc) but it isn't perfect. It would appear that some printing problems could occur. The GDI32.dll file is used commonly in Postscript printing, it would seem.

Administrators should NEVER push patches to large groups of computer without extensive and proper testing. This goes for ANY program (fix, patch, new program, update, upgrade, workarounds - whatever). Home-grown or official.

3) Take everything with a gain of Sodium Chloride (NaCl). The general media is great at taking any story and hyping it up. The WMF threat is real and it is dangerous, but it isn’t a RPC Buffer overflow. Remember Blaster & Sasser.

A freshly installed, up-to-date computer can not get infected without some form of user interaction. True, this interaction is small and likely to happen - if you plan on using your new shiny computer. =) Remember the ILOVE & Melissa viruses.

In the defense of the media however, most hype does start from inside the computer community itself. Professional that spend all days looking in the dark corners of the world for bad guys, will always see a threat like this as serious. The exploit code is everywhere, people do do whatever they want with it and post it everywhere, it is serious for corporate security professionals. They get paid to protect corporate assets and every threat must be battled. This fight isn't as direct in the home user world....

Sometimes hype is playing it safe...sometimes hype is good for selling products. Whatever you call it, hype brings security issues to the front page..which is something that is needed.

4) IMHO, home users are in much more danger than big corporate users. Most large companies have multiple defense systems and can reduce the WMF threat greatly without applying the suggested workarounds. Home users on the other hand, tend to be less informed and tend to already have a lot of “bad” stuff on their computers. Home users always want free e-mail smiley faces and free wallpapers and all the programs that could cause a security issue for large companies.

So in the end, practice safe hex, be prepared to battle any infection beyond the WMF and wait for Microsoft to release their patch on Tuesday.

Network and Security Professionals may want the extra protect of applying IIfak’s patch. Go ahead use it. All my home computers have it and my work laptop, but with multiple defense layers in place here at the office, I don’t see a huge need to push it out like its MS03-039.

Tuesday, January 3, 2006

Revision in WMF Vulerable Operating Systems - UPDATED

Larry Seltzer of eWeek reported on his weblog that only Windows XP and Windows Server 2003 are vulnerable in a practical sense.

It is true that this vulnerability is in GDI32.dll all the way back to Windows 3.0, but it would appear that Microsoft never set up WMF assocation before Windows XP. Therefore in older systems (Windows 2000/Me/98), the hole is there but much less of a direct threat.

It would seem that F-Secure and iDefense also agree with on this point.

Hopefully Microsoft will come out of the fog and start to see that allowing everything in the OS to run code by design isn't a good thing.

On a side note, HexBlog was taken down by its ISP for a short due to huge traffic flows. It would seem that Hexblog was slashdotted or dugg. =)

UPDATE - Alex Eckelberry of SunBelt has provided alternative download points for both the unofficial patch and checker.

UPDATE x 2 - Since high traffic make the ISP cut off Ilak's HexBlog. CastleCops has stepped up and offered him a home for now. See the new Hexblog forum.

Metasploit isn't a Virus

Richard M. Smith posted a rather funny message to the FunSec Mailing list this evening.
------------------------------------------
http://online.wsj.com/article/SB113630873566736620.html?mod=yahoo_hs&ru=yahoo

Microsoft Readies Fix As New Virus Spreads
By CHRIS REITER DOW JONES NEWSWIRES
January 3, 2006 1:20 p.m.

Microsoft Corp. plans to release on Jan. 10 a patch for a new Windows security flaw that is being exploited by a rapidly spreading computer virus strain known as "metasploit."

The virus surfaced last week as hackers took advantage of a flaw found in current server and desktop versions of Windows. It is considered serious because it requires relatively minor user interaction to be unleashed. The virus is carried in picture files and can be triggered if an image is viewed in an email or on an infected Web site.
---------------------------------------------

How could they be so wrong? Metasploit (MSF) isn't a virus, it is a tool (a pretty good tool IMHO). This tool does contain exploits that could be used combined with a payload to create a virus.

A tool is neither good nor bad, just like a knife itself is neither good nor bad. Tools are static; actions decide how the tool is viewed in most cases.

In court, a knife is seen as a "deadly weapon" but on Food TV, a knife is seen as an essential piece of equipment that no kitchen would dare be without.

Hopefully someone will point out the mistake to the WSJ. Metasploit is a very invaluable tool and it is sad to see its name misused this way.

When will WSJ report on the "PacketStorm" virus?? lol

Microsoft to Release Official WMF Patch on 10th

Updated Microsoft Security Advisory (912840) - Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution

"Microsoft has completed development of the security update for the vulnerability. The security update is now being localized and tested to ensure quality and application compatibility. Microsoft’s goal is to release the update on Tuesday, January 10, 2006, as part of its monthly release of security bulletins. This release is predicated on successful completion of quality testing."

What is Microsoft's response to Ilfak Guilfanov's Patch??

"Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on January 10, 2006.As a general rule, it is a best practice to utilize security updates for software vulnerabilities from the original vendor of the software. With Microsoft software, Microsoft carefully reviews and tests security updates to ensure that they are of high quality and have been evaluated thoroughly for application compatibility. In addition, Microsoft’s security updates are offered in 23 languages for all affected versions of the software simultaneously.Microsoft cannot provide similar assurance for independent third party security updates."

No real suprise. It isn't their patch so that was exepcted. No big deal.

I am still using Ilfak's patch and will leave it in place until next week - 10th.

Saturday, December 31, 2005

An Alternative Method of Fixing the WMF Vulnerability - UPDATED

I can't say it any better than the F-Secure blog said it. So here it is..
Here's an alternative way to fix the WMF vulnerability.

Ilfak Guilfanov has published a temporary fix which does not remove any functionality from the system (all pictures and thumbnails continue to work normally).

The fix works by injecting itself to all processes loading USER32.DLL. It patches the Escape() function in GDI32.DLL, revoking WMF's SETABORT escape sequence that is the root of the problem.

Now, we wouldn't normally blog about a security patch that is not coming from the original vendor. But Ilfak Guilfanov isn't just anybody. He's the main author of IDA (Interactive Disassembler Pro) and is arguably one of the best low-level Windows experts in the world.

More details from Ilfak's blog: http://www.hexblog.com.
Most people in the patch management world would never recommend a patch NOT from the original vendor, but Ilfak isn't just some kid. This is real...

If you test it, let me know how it works.

UPDATE - I have installed this on my personal laptop and seems to do exactly what it was meant to do. People that are serious about blocking this very danger attack should seriously look at this patch. Even the ISC has given it the go ahead.

They have earned my trust, that is for sure.

WMF Story - Day 4

1) Microsoft has updated their security advisory about the WMF. It now confirms that software-based DEP does NOT protect you from the WMF Exploit.

2) Also on FD, HD Moore has released an updated Metasploit 2.5 MWF Attack Module. This new version uses the "Escape/SetAbortFun code execution flaw" and pads the Escape() call with random WMF records.

3) Viruslist.com is reporting the first IM-Worm to exploit the WMF vulnerability. Appears to be spreading via MSN at this point, but i wouldn't be suprised to see copies on ICQ, AIM and Yahoo soon.

As far as I can tell, one of the biggest attack vectors is the IFRAME tag in a hacked/bad website.
As the number of attacks grow and become more and more nasty...we all wait for a patch. Do you think Microsoft will release it out of cycle? Who knows...

Friday, December 30, 2005

WMF Exploit Story - Day 3

Information is building and views are changing all the time. But everyone agrees that this WMF Zero-Day is nasty. Here is what we know on "WMF Day 3"


DEP Method

Sunbelt is reporting on their blog that the software-based DEP Windows XP SP2 method once suggested by Microsoft is not very effective. They found that hardware-based DEP is effective, but requires a CPU that supports it.

REGSRV32 Method

Bill Hayes pointed me to the latest F-Secure blog entry this morning. F-Secure found that the REGSRV32 workaround doesn't protect you from the WMF when using MSPaint. Great! lol

They suggest not using MSPaint at all for a while, which doesn't seem too difficult at this point.


It should also be stated that using Firefox does NOT protect you totally. Firefox is still open the WMF but it does require a bit more user interaction than IE – which requires zero. ;)

So the war isn’t over. But here are several suggestions that can only help the cause.

1) Always test any workaround before applying it to your network. This really applies to many things and it good all around advice.

2) Don’t trust one workaround to protection you totally. Apply the “Defense in Depth” idea to any threat. In the WMF case, this would include up-to-date antivirus on the clients and on the proxy edge. Use dynamic blocking of known sites with bad WMF using advanced (yet costly) proxy filtering software. Static block known sites if needed.

Here is an incomplete list

m.cpa4[dot]org
008k[dot]com
mscracks[dot]com
keygen[dot]us
dailyfreepics[dot]us
pornsites-reviews[dot]com
mmxo.megaman-network[dot]com
600pics[dot]com
Crackz[dot]ws
unionseek[dot]com
tfcco[dot]com
Iframeurl[dot]biz
beehappyy[dot]biz
Buytoolbar[dot]biz
teens7[dot]com
toolbarbiz[dot]biz
toolbarsite[dot]biz
toolbartraff[dot]biz
toolbarurl[dot]biz
buytoolbar[dot]biz
buytraff[dot]biz
iframebiz[dot]biz
iframecash[dot]biz
iframesite[dot]biz
iframetraff[dot]biz
iframeurl[dot]biz

Thursday, December 29, 2005

WMF Exploit hits Third-Party Ad Network

http://sunbeltblog.blogspot.com/2005/12/exfol-using-wmf-exploit-on-rotational.html

Man, this is just getting nasty...use Firefox.

CounterMeasures for the WMF 0-Day Exploit

1) Bleeding-Edge Snort has WMF exploit detection sigs for the open-source IDS known as Snort.

2) Combined those sigs with SunBelt's Free (or Full) Kerio Firewall, to help block and detect the WMF exploit. Get the how-to on the SunBeltBlog.

3) Disabling the library that contains the vulnerability will also work. From the ISC/SAN website. FYI - Infocon = Green
The vulnerability seems to be within SHIMGVW.DLL. Unregistering this DLL (type REGSVR32 /U SHIMGVW.DLL at the command prompt or in the "Start->Run" Window, then reboot) will resolve most of the vulnerability, but will also break your Windows "Picture and Fax Viewer", as well as any ability of programs like "Paint" and "Explorer" to display thumbnails of any picture and real (benign) WMF files.

"There is no Spoon" - Vanishing Teaspoons

Noticed this funny article on Scotsman.com and wanted to share it. We need some humor with all the bad Windows WMF stuff running around.

Viewing the article will require you to register your soul away, or you could just use Bugmenot.com - which is what I did.

Scientist cause a stir over vanishing teaspoons.

SCIENTISTS have proved what is common knowledge to most people - that teaspoons appear to have minds of their own. A study monitored the movements of 70 secretly numbered teaspoons over five months. Supporting expectations, 80 per cent of the spoons vanished during the period - although those in private areas lasted nearly twice as long as those in communal sections. "At this rate, an estimated 250 teaspoons would need to be purchased annually to maintain a workable population of 70 teaspoons," said researchers from the Macfarlane Burnet Institute for Medical Research and Public Health in Melbourne. Writing in the British Medical Journal, they said their research proved that teaspoons were an essential part of office life and the rapid rate of disappearance proved that this was under relentless assault. Regretting that scientific literature was "strangely bereft" of teaspoon-related research, the scientists offered a few theories to explain the phenomenon. Taking a tip from Douglas Adams's Hitchhiker's Guide to the Galaxy , they suggested that the teaspoons were quietly migrating to a planet uniquely populated by "spoonoid" life. They also offered "resistentialism", in which inanimate objects like teaspoons have an aversion to humans. On the other hand, they suggested, people might simply be taking them.


Wednesday, December 28, 2005

Microsoft Windows Zero-Day Making the Rounds - UPDATED

A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in the handling of corrupted Windows Metafile files (".wmf"). This can be exploited to execute arbitrary code by tricking a user into opening a malicious ".wmf" file in "Windows Picture and Fax Viewer" or previewing a malicious ".wmf" file in explorer (i.e. selecting the file). This can also be exploited automatically when a user visits a malicious web site using older versions of Firefox, current versions of Opera, Outlook and all current version of Internet Explorer on all versions of Windows.

Secunia has classified the vulnerability as "Extremely Critical". It is currently unpatched and being exploited in the wild to spread spyware and viruses.

HD Moore has included this new exploit in his Metasploit Framework. The exploit was discovered by "noemaipls" and released onto the Bugtraq Security Mailing List.

Sunbelt Software, makers of CounterSpy, has reported via the FD Security Mailing List seeing this exploited on multiple sites and increasing in use. They also provided several live links to the exploit.

UPDATE (12/28/05) -

Here is the Exploit on the French Security Incident Response Team (FrSIRT) website, a known exploit release site.

Here is a demo video of the exploit from Websense Security Labs.

UPDATE (12/29/05) -

Microsoft has released a Security Advisory titled "Vulnerability in Graphic Rendering Engine Could Allow Remote Code Execution".

All versions of Microsoft Windows are open to this attack. But several special features in Windows 2003 SP1 can mitigate the attack when the vector is e-mail.

CERT Vulnerability Note VU#181038

It has also been reported that Google Desktop may be another potential attack vector and that various anti-virus software products cannot detect all known variants of exploits for this vulnerability.

IMPORTANT NOTE - We must also remember that WMF files can pretend to be other image files (JPEG, GIF, TIF, etc). Just because the file is named .gif, doesn't mean it really is. Windows will read the inside the file, see that it is a WMF and run as normal.

SunBelt has released a

Thursday, December 22, 2005

Sacred Gospel of the Flying Spaghetti Monster Found!!

Ok, it wasn't found...but it is being written. Scheduled for publication in March.

Wired Article and interview with Bobby Henderson - Passion of the Spaghetti Monster

Learn more about the Chruch of the Flying Spaghetti Monster at Wikipedia

-Ramen

Tuesday, December 20, 2005

Its a Wonderful Internet - Happy Bedtime Story

Ok, more humor and fun. It shows you how much the internet has changed our world in that little kid bedtime story kind of way. =)

It's a Wonderful Internet

Thanks Todd P. for the link.

Thursday, December 15, 2005

Building the Real "A-Team"

Ok, so this is the "side of humor" entry. This is great. It cleared up my "case of the Mondays" on this week. Enjoy.

Finding The A-team: A Stuffo Experiment

New Metasploit Framework v3.0 Alpha Release 1

The Metasploit Framework (MSF) is an advanced open-source platform for developing, testing, and using exploit code. The MSF can be roughly compared to commercial offerings such as Immunity's CANVAS and Core Security Technology's Impact. The major difference between the Framework and these commercial products is the focus; while the commercial products need to provide the latest exploits and an intuitive GUI, the Framework was designed to facilitate research and experimentation with new technologies.

The original MSF was written in Perl scripting lanuage and included various components written in C, assembler, and Python. The new 3.0 branch was a complete rewrite of the 2.0 branch using the Ruby programming language.

The primary goals of the 3.0 branch are listed below:
  • Improve automation of exploitation through scripting
  • Simplify the process of writing an exploit
  • Increase code re-use between exploits
  • Improve and generically integrate evasion techniques
  • Support automated network discovery and event correlation through recon modules
  • Continue to provide a friendly outlet cutting edge exploitation technology

Remember this is a *alpha* release, so things will break. Help HD Moore by giving good quality feedback. It is almost crazy to see how this project has expanded and growth. Nice work indeed.

Sorry no Windows support yet, only Linux and Mac OX platforms with Ruby 1.8.x are supported.

Wednesday, December 7, 2005

Nmap 3.94 ALPHA3 Released - UPDATED

Update - Nmap 3.95 has been released, check out http://www.insecure.org/

Nmap is the de facto port scanner in existence today.

Fyodor recently released Nmap 3.94 ALPHA3. He spent all last weekend trimming its waistline. This should reduce the memory consumption on very large network scans. Remember this is an ALPHA release, so treat it as such.

Download Points

Linux Source - http://download.insecure.org/nmap/dist/nmap-3.94ALPHA3.tgz
Linux RPM - http://download.insecure.org/nmap/dist/nmap-3.94ALPHA3-1.src.rpm
Windows Binary - http://download.insecure.org/nmap/dist/nmap-3.94ALPHA3-win32.zip

Nice work Fyodor. Thanks Harlan for catching my error, even if I was late to fix it.

Thursday, December 1, 2005

UPDATED - Gmail to Include Anti-Virus Scanning Soon

Like Yahoo Mail, Gmail will soon start to scan all attachments for viruses. Any detect viruses will be cleaned or deleted. As far as I can tell, it doesn't sound like there is a way to disable this feature - which is sad but understandable.

Since it was first created, Google has locked down some of the "nice" features of Google in the name of security. For example, Zip files are blocked, but this is easily bypassed by renaming the file.

Looks like if you want to trade exploit code or new malware on Gmail, you will need to get your GPG up and working if you want to continue.

Google is not just increasing the security of the free service; they are adding many cool features as well. I really like the AutoSave feature - oh and the 2.5 GB of storage.

Question of the Day - Which Anti-virus product will Google license for Gmail? Sophos? F-Secure? Kaspersky? Trend Micro? Or will it be one of the US Standards - McAfee & Symantec.

UPDATE - Ryan over at thebillygoatcurse.com ran a series of tests and decided that Gmail is using Sophos. His results are very interesting. Thanks Michael for the information.

Tuesday, November 29, 2005

FCC Expected to Back Pay-Per-Channel Cable TV

Wall Street Journal is reporting that the Federal Communications Commission (FCC) is expected to back 'a la carte' pricing in the industry, instead of bundled channels. Last years' FCC report on the subject found that most U.S Households would face higher television bills if they only paid for the channels they wanted to watch. However, the FCC is now releasing a revised report that will conclude just the opposite.

Pay-Per-Channel does better serve the customer IMHO. This is long overdue too. I live in Texas but really do not know that much Spanish, so why do I have two/three Spanish channels on my extended cable? Why am I paying for them? Good Question.

FireFox 1.5 - Releasing Today?

LinuxWorld.com is reporting that Firefox will be released on Tuesday (today). Another false release? I guess we can only wait and see.
After a host of test releases and one false start, a new version of the Firefox browser will be ready on Tuesday, according to a media alert issued by the Mozilla Foundation.

Firefox 1.5 will be available for free on Tuesday afternoon, U.S. Pacific Standard Time, at
www.getfirefox.com and www.mozilla.com, according to the open-source group. A complete press release outlining the new features in Firefox 1.5, as well as some additional Mozilla news, will be issued tomorrow at the time the new version is available.

Tuesday, November 22, 2005

EFF Files Class Action Lawsuit Again Sony BMG

The Electronic Frontier Foundation (EFF), along with two leading national class action law firms, yesterday filed a lawsuit against Sony BMG, demanding that the company repair the damage done by the First4Internet XCP and SunnComm MediaMax software it included on over 24 million music CDs.

When MediaMax software doesn't contain as many "magic tricks" as the XCP software, it is on over 20 million CDs - ten times the number of CDs as the XCP software.

MediaMax installs files on the users computer even if they click "No" on the EULA and like the XCP, does not include a way to fully uninstall the program. Both MediaMax and XCP send data back to their owners, allowing them to track user listening habits at the flip of a switch - even though the EULA states that the software will not be used to collect personal information.

Remeber the XCP EULA states that Sony is never liable to the customer for more than 5 dollar. Would Sony like to tell me where a computer can get repaired for 5 dollars??

The EFF - Defending Freedom in the Digital World.

Monday, November 21, 2005

State of Texas Sues Sony BMG over XCP

Texas Attorney General Greg Abbott today sued Sony BMG Music as the first state in the nation to bring legal action against Sony for its rootkit XCP DRM software.

This suit is the first filed under the state's spyware law of 2005. It alleges the company surreptitiously installed the spyware on millions of compact music discs (CDs) that consumers inserted into their computers when they play the CDs, which can compromise the systems.

“Sony has engaged in a technological version of cloak and dagger deceit against consumers by hiding secret files on their computers,” said Attorney General Abbott. “Consumers who purchased a Sony CD thought they were buying music. Instead, they received spyware that can damage a computer, subject it to viruses and expose the consumer to possible identity crime.”

Because of alleged violations of the Consumer Protection Against Computer Spyware Act of 2005, the Attorney General is seeking civil penalties of $100,000 for each violation of the law, attorneys’ fees and investigative costs.

This is a bold step taken by the state of Texas. Makes me proud to be a Texan. I wouldn't be surprised to see other states file suits as well. Many states passed similar anti-spyware legislation in 2005.

See the full lawsuit in PDF form. After reading the text, I don't see any possible way the state could lose.

XCP DRM Defeated by a "Piece of Tape"

Vnunet.com has a very interesting aritcle about another XCP discovery. It isn't a new feature of the XCP rootkit, but the discovery that a very old anti-DRM trick still works.

Researchers at Gartner released this information just today.
Applying a piece of opaque tape to the outer edge of the disk renders the data track of the CD unreadable. A computer trying to play the CD will then skip to the music without accessing the bundled DRM technology.

"After more than five years of trying, the recording industry has not yet demonstrated a workable DRM scheme for music CDs," Gartner concluded in
a newly published research note.

The use of a piece of tape will defeat any future DRM system on audio CDs designed to be played on a stand-alone CD player, the analyst said.
How can these DRM scheme really be worth all the money, if they are easily bypassed by a peice of tape, a magic marker or the "SHIFT" key??

Thursday, November 17, 2005

Sony Story Gets Going - Enter MediaMax

While Sony was slow to response to the initial story of the XCP, it seems they are finally putting their money where their mouth should have been all along. This story proves that the blogosphere can make a difference in a very huge way.

Sony have taken several very positive steps in the last few days -

1) Along with an open letter to their customers, Sony has released a list of the CDs that contain the XCP DRM software - all 52 of them.

2) Not only has Sony recalled all these CDs from the stores, but they will also provide customers a free XCP-free replacement.

3) Sony states they will be releasing a complete and "secure" XCP uninstall program in the near future as well.

Sony must not be allowed to sweep their under the "carpet". Dan Kaminsky has produced an extremely striking picture of the geographic extent of rootkit-related DNS traffic. Dan collected this information in a process called DNS Cache Snooping. While these steps should be seen as a positive step in the right direct, the real case is not closed just yet.

The information against Sony keeps coming in and the world keeps fighting. Soon Sony's other DRM software, MediaMax, will be all over the news as well.

J. Alex Halderman released information today on his Freedom-to-tinker blog, that the web-based uninstaller used to remove the MediaMax DRM software opens up a major security hole very similar to the one created by the web-based uninstaller for Sony's XCP. He has verified that it is possible for a malicious web site to use the SunnComm hole to take control of PC where the uninstaller has been used. In fact, he states that the SunnComm problem is easier to exploit than the XCP uninstaller flaw. Secunia has released an advisory on this highly critical vulnerability.

EFF is collecting stories from EFF members and supporters who have purchased Sony-BMG CDs that contained SunnComm's MediaMax copy protection software. The MediaMax software is somewhat different, but similarly has no true uninstall option and establishes an undisclosed ongoing communication from the users’ computer to SunnComm. CDs with this technology include:

Amici Forever, Defined
David Gray, Life in Slow Motion
Foo Fighters, In Your Honor
My Morning Jacket, Z
Santana, All That I Am
Sarah McLachlan, Bloom Remix Album

Apple/Mac users that laughed about the XCP story can now join in on the fight against Sony, since MediaMax has been Apple/Mac compatible since 2003.

Right in the middle of this battle, the House Subcommittee on Commerce, Trade, and Consumer Protection heard from witnesses discussing "Fair Use: Its Effect on Consumers and Industry." on Wednesday.

While that the blogs and the stories will fade, it is very important that people know their rights and learn to defend those freedoms even in the face of a corporate giant, like Sony.

Wednesday, November 16, 2005

Exploit of the Sony/First 4 Internet ActiveX Control in the Wild

Active exploits of the "Uninstall" ActiveX Control Vulnerability have been found in the wild.

Websense Labs have recieved reports of websites that are using the Sony DRM "Uninstaller" vulnerability as a means to perform malicious actions on end user machines.

Remember this ActiveX control will only be present on your system if you used Sony's web-based XCP decloaker.

But why use another Sony program to decloak Sony's XCP rootkit?

I would use one of the many third-party decloaking utilities, like Sophos' UnMaking Tool.

Once it is decloaked, you still have to ask yourself the following.

"Am I comfortable with the Sony's XCP software on my computer? "

Tuesday, November 15, 2005

Sony's Wants to Kill Your Computer - Again

Remember the Sony web-based "patch" that removed the cloaking ability of the XCP rookit and updated all the files to XCP2?

It appears that if you believed the magic words of Sony and ran the web-based patch, you may have dug a larger security hole into your computer than the original cloaking rootkit itself.

A post co-written by Ed Felten & J. Alex Halderman over at Freedom to Tinker explains the new security threat posed by the CodeSupport ActiveX control.

The root of the problem was in a serious security flaw in Sony's web-based uninstaller patch. When you first fill out Sony’s form to request a copy of the uninstaller, the request form downloads and installs a program – an ActiveX control created by the DRM vendor, First4Internet – called CodeSupport. CodeSupport remains on your system after you leave Sony’s site, and it is marked as safe for scripting, so any web page can ask CodeSupport to do things. One thing CodeSupport can be told to do is download and install code from an Internet site. Unfortunately, CodeSupport doesn’t verify that the downloaded code actually came from Sony or First4Internet. This means any web page can make CodeSupport download and install code from any URL without asking the user’s permission.

In short, this is the situation that Sony has created for THEIR CUSTOMERS that currently have the CodeSupport ActiveX control installed -

1) A malicious website author can write a malware program.

2) Package it up and throw it on some URL.

3) Trick the user into visiting the site that calls the above URL using IE. (Think Phishing or Pharming)

As soon as you visit the evil site, the package is downloaded to your computer and executed automatically without the user seeing a thing. You now have a non-sony rootkit/keylogger/bot installed on your computer. Thanks again Sony. Depending on the target range of the attack, the now installed malware may not even be detected by anti-virus.

Sony has again heard the voices of the public and provided an EXE version of this uninstaller patch. As long as you have never used the web-based patch, then you should be safe from this new threat.

If you think you might have the CodeSupport ActiveX installed, try Muzzy Reboot Test.

After infecting more than half a million networks, including military and government, Sony has decided to pull the XCP CDs off the shelf.

For now, pulling the CDs off shelves "could go a long way toward making a consumer feel comfortable that the CD they just purchased isn't going to mess up their computer," says record store owner John Kunz of Waterloo Records in Austin.

If you ever feel the need to dig for vinyl records, Waterloo and Alien are both great Austin stores.

Microsoft has finally jumped in the game and joined the rest of the anti-spyware world in its view of the Sony Rootkit. Microsoft will include removal signatures for the Sony rootkit in the Windows AntiSpyware beta, the Malicious Software Removal Tool, and the Windows Live Safety Scanner. Good news for many Windows users.

To top off all the lawsuits currently in the works against Sony, a Dutch article was released today that indicates that Sony may have used the LAME LGPL mp3 encoder in their rootkit. If this is true, then Sony failed to follow the rules for using open-source software, therefore putting it in direct violation of the open-source license agreement.

Friday, November 11, 2005

Reaction to Sony's "Magic" makes Sony Halts Production of XCP CDs

It would appear that Sony has heard the public and the world for once. They have decided to suspend the manufacture of CDs containing XCP technology. They have finally decided to put a link to their "patch" on their website also. Brilliant..and why did they not do that from the start? I wouldn't even call it a patch - more like an upgrade to XCP2 with the cloaking.

It seems that the global security reaction to Sony's magic tricks was enough to make them stop and think about their actions - for once. In my mind, I see Sony rolling its sleeves up and saying "nothing up my sleeve".

Digital-rights advocates and consumers attorneys are preparing nearly a half dozen legal actions against the music giant. Included in the legal actions are the following -

  • Chicago-based law firm Cirignani Heller Harman & Lynch may be filing a class-action law suit.
  • San Francisco-based law firm Green Welling will be filing a class-action law suit against Sony to recover damages caused by consumers by the XCP CDs. The lawsuit alleges that Sony BMG has broken three Californian laws.
  • Italian digital rights group Associazione per la Libertá nella Comunicazione Elettronica Interattiva (ALCEI) filed a criminal complaint with that nation's Economic and Financial Police Division to investigate whether Italy's consumers were affected by the Sony BMG cloaking technology and, if so, whether the company, and any other music company, violated national laws and should be prosecuted.
  • Electronic Frontier Foundation (EFF) is collecting stores from EFF members and supporters who have purchased Sony BMG CDs that contained the XCP technology. They are considering litigation against Sony but have not made a final decision on the issue.
  • New York lawyer, Scott Kamber, is planning a class-action lawsuit for all Americans affected.

Antivirus and Anti-Spyware vendors are taking action as well.

There is even an online Sony DRM Boycott petition, if you want to personally express your unhappiness in the public eye.

It is my belief that Sony knew they were going into untouched waters with this rootkit-like technology, but I do also believe that they do not understand the security issues related to releasing a tool of this nature. Within the last two days, several bots have been released that are using the Sony DRM cloaking code to hide and infect users with very evil stuff.

I can only assume that spyware makers and botnet writers will start using Sony's DRM cloaking as soon as possible. They already jump on every new IE exploit like it is gold, why whould this be any different? Did Sony not see this happening? Where were they?

They are busy staring at their bottom line...and it is above to drop... like it's hot.

Thursday, November 10, 2005

Sony DRM / Rootkits - Why You Need to Care

In August 2005, I received a virus alert in my e-mail. It was from a computer in the financial department - it was infected with a rootkit. Not the best way to start out a day, but stuff happens. We looked over the file and I reported it to our anti-virus vendor. The vendor responded that it was not a false positive and that we should treat it like a normal rootkit. Here was the detection -

Virus Troj/RKProc-Fam detected in:"C:\WINNT\system32\$sys$filesystem\aries.sys"
Disinfection unavailable.

Thanks to my friends at TRE Research for reverse engineering the above file with IDA Pro. Check that out here.

The threat was removed but I kept the file for several months. On Nov 9th, I tested the file at VirusTotal.com and it was no longer detected as a rootkit. Study the filename closely and remember it as you read the rest of this blog.

On the morning of October 31, I started my day like every other day. I was looking over the standard security websites, reading Full-Disclosure and drinking my coffee. I ran across Mark Russinovich's Blog that morning but my eye didn't get past the title for some reason. I was asked to work on a network device, so I started my day.

But later I came back to Mark's blog entry for Oct 31 and was very impressed with what he had found. In the process of testing the latest version of Sysinternals' RootKit Revealer, he had discovered hidden software on his computer. Mark, like many in the security community, does not like to find surprises hiding in his computer. He started a basic forensic breakdown on the software and found that it was connected to a company not normally known for its rootkit technology - Sony BMG.

Digging deeper, he found that the main driver of the rootkit (aries.sys) was designed by the UK firm - First 4 Internet. This driver is part of a new Digital Rights Management package from Sony called Extended Copy Protection (XCP). This new software is installed onto your computer when you attempt to listen to certain copyright-protected music CDs. When the CD is inserted into the computer, it automatically runs the software and presents the user with a common End User License Agreement. The EULA tells the user that a special player needs to be installed to listen to the CD but fails to fully describe the "player" software. If you agree to the install, the software installs itself onto the computer, hooks its "claws" into the kernel and cloaks itself using standard "rootkit technology".

"Root technology" in a simple yet very broad sense can be seen as a piece of software that hooks into the lowest level of a computer and attempts to cloak itself using many techniques. In general this cloaking ability will enable a piece of software to hide form the operating system itself and even lie about its existence to applications that run at "levels" higher than itself. This means that the rootkit can lie to anti-virus, running process detection software, anti-spyware and other applications that may hint at its existence. But you have to remember, the hooking is separate from the cloaking. Kernel hooking is in itself a valid programming technique used by some anti-virus vendors, anti-spyware vendors and IDS/IPS vendors.

This is where the water gets dirty however. Sony's rootkit driver cloaks ANY file or folder that has $sys$ in the filename. Sony stated that the cloaking rootkit does not increase the security risk to normal user, but I will state the opposite. This does make a computer more vulnerable overall and puts the casual user in greater risk. I also stated this fact in a small e-mail interview with TechTarget/SearchSecurity.com yesterday.

Sony's statement about the security risk only proves to the public that they do not understand the security risk of their rootkit-technology. Sony mislead the public about the risk only to save its image (aka bottom line), nothing more. If they are aware of the increased risk, then this proves they lied to the public. If they are not aware of the increated risk, this proves they do not understand the technology they are forcing onto millions of computers and therefore should have never started down this road in the first place.

Just today, a Trojan was discovered using Sony's cloaking driver to hide itself. This Trojan would normally have to contain code to hook itself into the kernel. But who needs the code, when Sony already has the hooks in place. The Trojan only needs to have $sys$ it its name to hide from the user and operating system.

Under the recent public pressure, Sony and First 4 Internet have released a "patch" that decloaks the DRM software but doesn't remove it at all. It actually updates the DRM software to new versions.

Sony's rootkit-like tricks are not the real legal problem however. There are two main legal problems with Sony's actions -

1) Sony's attempt to mislead the public about the software and its security risk - multiple times.
2) Sony's lack of information discourse in their EULA about the true nature of the software and how it is impossible to remove for a normal computer user.

See the Electronic Frontier Foundation's report on the Sony BMG EULA.

A class-action lawsuit has been started in the state of California, a nationwide class-action lawsuit is expected to be filed in the state of New York this week and there could be criminal cases bought against Sony under the "U.S. Computer Fraud and Abuse Act" and the UK's "Computer Misuse Act of 1990". Italian police have been asked to by the ALCEI-EFI in Italy to investigate Sony DRM code as well.

Computer Associates International said today it is now classifying Sony's software as spyware and will begin searching for and removing XCP with its anti-spyware software, starting on November 12. I can only hope that other vendors will follow suit.

How much trouble will Sony get into? Only time will tell...

In the meantime, conduct a simple test on your computer. Create a new folder on your desktop and name it test. Then rename the folder to $sys$test. If the folder disappears, your computer is infected with Sony's new DRM software. Then do two things -

1) E-mail Sony to thank for putting your system at increased security risk.
2) Wipe your computer and install everything fresh or use Sophos' UnMasking Tool to decloak the DRM Software. It will not remove it however.