Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

February 2006 - Posts

New Bagle.DP Variant - "February Price" theme
While most companies can effectively block this, it may be tough in cases where ZIP attachments are allowed and AV signature files haven't been published yet. The golden rule is to never open attachments.

New Bagle.DP Variant - "February Price" theme
http://secunia.com/virus_information/26794/bagle.dp/
http://vil.nai.com/vil/content/v_138366.htm

EMAIL FORMAT TO BLOCK OR AVOID

From: [SPOOFED]

Subject: price, February price

Message body: price, February price

Attachment:
price.zip
pricelst.zip
pricelist.zip
price_lst.zip
new_price.zip
21_price.zip
February price.zip
February_price.zip
Unpatched Windows SSDP/UPnP local vulnerability & POC Exploit

Thankfully, this new vulnerability is not remotely exploitable 

Microsoft Windows SSDP and UPnP Services Privilege Escalation Issue
http://www.frsirt.com/english/advisories/2006/0417

Advisory ID : FrSIRT/ADV-2006-0417
CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable
: No
Locally Exploitable : Yes
Release Date : 2006-02-02

EXPLOIT: POC exploit code can be found at FrSIRT

Technical Description: A vulnerability has been identified in Microsoft Windows, which could be exploited by malicious users to obtain elevated privileges. This flaw is due to an access validation in the Simple Service Discovery Protocol (SSDP) Discovery and the Universal Plug and Play Device Host (UPnP) services that fail to properly validate user permissions, which could be exploited by local unprivileged attackers to bypass security restrictions and execute malicious programs with elevated privileges.

More Posts « Previous page