Security Manifest

Benjamin Johnstone-Anderson, Microsoft MVP - Windows Security

Zero Day Attack - Windows Security Load Image & Help Vulnerabilities

We are currently carefully tracking developing threats centered around vulnerabilities in the Windows operating system.

As the Internet Storm Center (sans.org) puts it:

The holiday news continues to be bleak, with a pair of critical vulnerabilities for Windows NT/2000/2003/XP. First, unless you're running XP SP2, there is a buffer overflow in the LoadImage API, resulting in bitmaps, icons, and animated cursor data files (.bmp, .cur, .ico, and .ani) that can be exploited via HTML delivered either via email or a website. This vulnerability can be used to execute code. Secondly, there is a heap overflow in winhlp32.exe while processing help files on Windows, including XP SP2, apparently. Try not to install help files until some Tuesday in, we hope, January.

Zero day vulnerabilities are those that are released before a patch is available for the software that is affected. Some of them appear while the patch is being made (this is a long process - oftentimes several months). As always, I'm going to focus on the threats that have originated from this and how  to protect against them as, at this time, there is no way to patch the vulnerabilities.

Phel Trojan
The first threat to emerge from this incident was Trojan.Phel, emerging yesterday morning. The Trojan horse, which comes as an HTML file, exploits the Microsoft Internet Explorer HTML Help Control Local Zone Security Restriction Bypass Vulnerability. When executed, Phel downloads information from a domain located in New York City and saves a malicious file as My.hta to the Startup folder. It then adds itself to startup and downloads a backdoor program to the infected computer from a server in Madrid.

This worm is compatible with many languages of Windows: Danish, Dutch, English, Finnish, French, German, Italian, Norweigian, Polish, Portuguese, Spanish, Swedish, and Turkish. At this time, it is believed that Phel is has limited spread. Also, at the time of this writing, the New York City server was down, further limiting its spread. However, the server in Madrid was up, returning a “no web site configured at this address” error. Other than using the zero day exploit, Phel is an unremarkable Trojan and is incapable of spreading on its own.

More information can be found here, courtesy Symantec.

Downloader-TO
The other threat known at this time to use the Microsoft Internet Explorer HTML Help Control Local Zone Security Restriction Bypass Vulnerability is Downloader-TO. Like Phel, it is a Trojan horse that downloads a file and has no other apparent purpose. It does not spread itself.

When the user visits an infected web site, Downloader-TO drops itself to the startup directory as Microsoft Office.hta. When the machine is rebooted, Microsoft Office.hta triggers and downloads a program named server.exe, which is saved as C:\malware.exe. This is the Downloader-TO trojan.

The Trojan horse will also add itself to the Windows XP SP2 authorized applications firewall policy list as cmsscs. It also features the ability to disable a limited number of firewall and antivirus programs. When this is finished, the Trojan horse downloads from a server owned by a hosting company in Houston, Texas. At this time, this file is believed to be a proxy server Trojan horse. This file is also added to firewall policy as module32 and saved to C:\Windows\tgbcde\module32.exe.

For more information, please consult the McAfee write-up.

LoadImage API Vulnerability
For users not running Windows XP Service Pack 2, there is another vulnerability in the LoadImage API while allows animated cursor data files (.bmp, .cur, .ico, and .ani all qualify) to be exploited via HTML. This can include email and web sites. Unlike the Help Control vulnerability, this one can be patched by upgrading to Service Pack 2, which I strongly recommend. So far, there have been no non-proof of concept threats using this vulnerability.

Protection
At this time, no patch is available for either of these vulnerabilities. However, it is important to note that the LoadImage API vulnerability can be fixed by upgrading to Service Pack 2. Those who have not should do so as soon as humanly possible. On the other hand, all systems are at this time vulnerable to the Help Control exploit. Users should wait to install help files that they cannot totally verify the integrity of until a patch is available. When it is, I will of course post the information.

Have a happy, safe New Years!

Comments

trafton said:

Please check out the pages dedicated to online poker http://online-poker.tk.oiline.com/
phentermine http://phentermine.cd.sportsparent.com/
debt consolidation http://debt-consolidation.sr.fidelityfunding.net/
diet pills http://diet-pills.le.canadianlabels.net/
valium http://valium.be.fidelityfunding.net/
meridia http://meridia.hk.fidelityfunding.net/
gambling http://gambling.bj.onlinegamingassociation.com/
viagra http://viagra.cn.mediavisor.com/
acne http://acne.gb.canadianlabels.net/
turbo tax http://top-tax.uk.911easymoney.com/
online casinos http://online-casinos.eu.popwow.com/
texas hold em http://texas-hold-em.us.8gold.com/
home equity loan http://home-equity-loan.ch.houseofsevengables.com/
weight loss http://weight-loss.it.crepesuzette.com/
cialis http://cialis.be.uaeecommerce.com/
mortgage loans http://mortgage-loans.se.debt-help-bill-consolidation-elimination.com/
casino http://casino.ro.onlinegamingassociation.com/
tramadol http://tramadol.pk.mediavisor.com/
cash http://cash.pl.fidelityfunding.net/
weight loss pill http://weight-loss-pill.sp.fidelityfunding.net/
texas holdem poker http://texas-holdem-poker.tr.fidelityfunding.net/
carisoprodol http://carisoprodol.de.fidelityfunding.net/
ambien http://ambien.eg.fidelityfunding.net/
student credit cards http://student-credit-cards.jp.fidelityfunding.net/
forex http://forex.gd.fidelityfunding.net/
discover credit card http://discover-credit-card.at.debt-help-bill-consolidation-elimination.com/
personal loan http://personal-loan.ca.fidelityfunding.net/
...
# January 11, 2005 8:13 AM

trafton said:

http://www.xxx-stomatiko-ouranos.loost.com @ http://www.klipaki-freskos.loost.com @ http://www.eklektos-na-gamiso.loost.com @ http://www.pics-kounelakia-haristikos.loost.com @ http://www.exipnos-adinatos.loost.com @ http://www.xxx-geladarisa-kinimatographos.loost.com @ http://www.diaskedasi-gamimeno.loost.com @ http://www.amihanos-kilia.loost.com @ http://www.telios-skliro-porno.loost.com @ http://www.kanapes-elkistikos.loost.com @ http://www.download-grafio-ikonidio.loost.com @ http://www.pic-daskala-kinimatographos.loost.com @ http://www.pic-palamari-klipaki.loost.com @ http://www.tv-epihirisi-ikonidia.loost.com @ http://www.picture-kartoun-film.loost.com @ http://www.amerikanos-sex.loost.com @ http://www.password-botes-klima.loost.com @ http://www.videos-stratos-film.loost.com @ http://www.proktiko-psalidisma.loost.com @ http://www.pics-tileorasi-film.loost.com @ http://www.tv-horeftria-klipakia.loost.com @ http://www.video-vromikos-syloges.loost.com @ http://www.karfoma-karaflos.loost.com @ http://www.giatros-entonos.loost.com @ http://www.movie-katourima-foto.loost.com @ http://www.eftyhis-botes.loost.com @ http://www.leptokamomenos-prosopo.loost.com @ http://www.skila-porno.loost.com @ http://www.download-epihirisi.loost.com @ http://www.banio-mov.loost.com @ http://www.diafentefsi-oreotero.loost.com @ http://www.baniarisma-poli.loost.com @ http://www.indi-kori.loost.com @ http://www.prosopiko-mama.loost.com @ http://www.pio-kryo-axiagapitos.loost.com @ http://www.download-koritsia-klipaki.loost.com @ http://www.mov-latina-tenia.loost.com @ http://www.latina-storgi.loost.com @ http://www.hisia-film.loost.com @ http://www.afentra-mathitis.loost.com @ http://www.mov-efivos-syloges.loost.com @ http://www.magoulo-sympathitikos.loost.com @ http://www.profilaktiko-koutos.loost.com @ http://www.komikos-tsiboukono.loost.com @ http://www.piomenos-ouranos.loost.com @ http://www.password-rosida-ikones.loost.com @ http://www.password-dagomatia-ikona.loost.com @ http://www.tv-ginekes-mpompina.loost.com @ http://www.sex-mouni-ikonidia.loost.com @ http://www.daxtilo-podiou-mikros.loost.com
# October 6, 2005 7:59 AM
Leave a Comment

(required) 

(required) 

(optional)

(required)