Windows (all versions) Zero Day lnk vulnerability VERY serious


Recommended Posts

I know it was posted on the front page that Microsoft Released a fixit tool to turn off your icons until a fix is released.

Just to recap

Computerworld - Microsoft on Friday warned that attackers are exploiting a critical unpatched Windows vulnerability using infected USB flash drives.

The bug admission is the first that affects Windows XP Service Pack 2 (SP2) since Microsoft retired the edition from support, researchers said. When Microsoft does fix the flaw, it will not be providing a patch for machines still running XP SP2.

In a security advisory, Microsoft confirmed what other researchers had been saying for almost a month: Hackers have been exploiting a bug in Windows "shortcut" files, the placeholders typically dropped on the desktop or into the Start menu to represent links to actual files or programs.

"In the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware," Dave Forstrom, a director in Microsoft's Trustworthy Computing group, said in a post Friday to a company blog. Stuxnet is a clan of malware that includes a Trojan horse that downloads further attack code, including a rootkit that hides evidence of the attack.

http://www.computerworld.com/s/article/9179512/Microsoft_warns_of_Windows_shortcut_drive_by_attacks

Most people didn't seem to concerned because they weren't inserting removable media into their machine. As it turns out there has been some speculation that a machine could also be compromised using this vulnerability via the icons you get while browsing to different websites.

Microsoft said ""An attacker could also set up a malicious Web site or a remote network share and place the malicious components on this remote location," the company said in the advisory. "When the user browses the Web site using a Web browser such as Internet Explorer or a file manager such as Windows Explorer, Windows will attempt to load the icon of the shortcut file, and the malicious binary will be invoked."

On the security now podcast Steve Gibson said

The act of displaying the icon of the link files executes the malicious code in that new machine. It's regarded as not requiring any specific user action. So in this particular case it's being considered a worm. And something like 9,000 instances of this a day is now being seen in the wild. The point is that everyone who recognizes how pervasive this can be is expecting this to be a big problem. And Microsoft in their most recent update acknowledged something that HD Moore was first quoted as saying. He has apparently figured out how to get favicons to do this.

Leo: Ugh. So websites would do it, then.

Steve: Yes. And so Microsoft has acknowledged that not only displaying these .LNK file icons in Windows Explorer, but now in Office documents, any Office documents are also vulnerable, including Outlook, which is to say email. So receiving malicious email containing one of these can compromise your system. And they also acknowledge websites can do it. You can now have a malicious website that will display, that will leverage this through the defect in the shell. And I'm not sure if it's all browsers. Certainly IE because Microsoft has acknowledged that. Depending upon where the display code is, I would imagine this may be cross-browser vulnerable also. We'll know more certainly a week from now.

The problem is that there isn't anything clearly - there's no real good solution for this. Microsoft has posted a Fix it which makes some changes to the registry and also shows what manual changes can be made. The problem is that the fix that is required, until we actually get the problem repaired, is that all of your link, all of your shortcuts stop being displayed, and you get sort of the generic white rectangle.

Just thought I would give everyone the heads up.

I agree, too many people were fixated on the USB plugging thing.

The flaw is serious.

The exploits are being used.

I would expect a fix from Microsoft soon. Quite likely an out-of-band patch before Patch Tuesday.

"IE8 still requires confirmation before going from Internet zone to [a] WebDAV share," he said, referring to an Internet Explorer security setting. "It is an easy drive-by on IE6, but there is still user interaction with newer versions of IE."

The attack doesn't work when users browse with Mozilla's Firefox or Google's Chrome, Moore said.

Although I could see this being exploited by inserting it into legit programs. I know a while back wordpress's website was hacked and malicious code was added. Except in this case, it would replace the shortcut icon of a popular program.

So, I skimmed it all - read it, but fast, as I am very busy; I have two questions:

Can this worm affect my system by me just simply browsing websites? (I'm concerned here, as I browse a lot of porn).

Will it be obvious if I am infected by this? (I think read something which stated that all my icons would turn into a generic paper icon or something).

Thanks, guys :)

Can this worm affect my system by me just simply browsing websites? (I'm concerned here, as I browse a lot of porn).

No. You have to connect to a WebDAV share using IE. IE 8 requires confirmation before doing this, but IE 6 doesn't. So as long as you're using IE 8 or a none IE browser you should be safe.

As long as an Explorer window tries to read the shortcut file's icon data, it's subject to the exploit. Yeah, WebDAV shares are coincidentally affected (since Windows uses Explorer to connect to WebDAV shares) which makes this a potential remote exploit, but other stuff too, like network shares etc, besides the obvious stuff like being subject to the vulnerability merely by extracting a zip file and viewing its contents (with among others, a malicious shortcut) in Explorer. Note: Looking at the icon is enough, you don't need to open stuff.

Lots of possibilities here, which make it so serious. It's hard to predict all attack vectors... Browsing files in a third party app is also subject to the exploit, I suppose, since they usually use the standard "Open file" dialog box, and I think that one also parses icon info.

No. You have to connect to a WebDAV share using IE. IE 8 requires confirmation before doing this, but IE 6 doesn't. So as long as you're using IE 8 or a none IE browser you should be safe.

Excellent; thank you for the information :happy:

:rofl:

Well, honesty is the best policy!

(Y) :D

So, I skimmed it all - read it, but fast, as I am very busy; I have two questions:

Can this worm affect my system by me just simply browsing websites? (I'm concerned here, as I browse a lot of porn).

Will it be obvious if I am infected by this? (I think read something which stated that all my icons would turn into a generic paper icon or something).

Thanks, guys :)

No, you might only know after your personal data is stolen (credit card information, bank credentials, passwords, ...).

ok WebDAV shares is one thing

but the way I understood it, the vulnerability could also affect favicons like this.

The act of displaying the icon of the link files executes the malicious code in that new machine. It's regarded as not requiring any specific user action. So in this particular case it's being considered a worm. And something like 9,000 instances of this a day is now being seen in the wild. The point is that everyone who recognizes how pervasive this can be is expecting this to be a big problem. And Microsoft in their most recent update acknowledged something that HD Moore was first quoted as saying. He has apparently figured out how to get favicons to do this.

See why this is really scary now?

post-4927-1280017181821.jpg

post-4927-12800172985075.jpg

He has apparently figured out how to get favicons to do this.

If that is true, then this is incredibly catastrophic. All Windows users should stay away from the Web, or apply the MS suggested solution that eliminates the icons (does it get rid of the favicons too?).

If that is true, then this is incredibly catastrophic. All Windows users should stay away from the Web, or apply the MS suggested solution that eliminates the icons (does it get rid of the favicons too?).

People don't read. It's only a major issue if you're still using IE6 (which if you are you aren't really worried about security anyway) - later versions of IE aren't that severe and other browsers aren't affected.

People don't read. It's only a major issue if you're still using IE6 - later versions of IE aren't that severe and other browsers aren't affected.

Where does it say that? IE6 doesn't ask you permission to connect to a WebDav share, that's why it's more serious when using that version of IE ( when the infection vector is WebDav shares ). The favicons are displayed in every browser.

You apparently didn't read that part.

Firefox doesn't support WebDAV, and I don't think its FTP support parses icons but uses hard coded icons depending on file extensions.

Firefox "supports" WebDAV, in the sense that WebDAV is a set of extensions to HTTP, so the core protocol is the same.

And yeah, Firefox doesn't show "embedded" icons when using FTP and such, but more importantly it doesn't use the Windows icon decoder, so a flaw in that wouldn't effect Firefox.

And yeah, Firefox doesn't show "embedded" icons when using FTP and such, but more importantly it doesn't use the Windows icon decoder, so a flaw in that wouldn't effect Firefox.

Never the term "Internet Explorer" made so much sense. :laugh:

Edited by Rob2687

It never has, except maybe to some obtuse individuals. I think it's safe to say you've never heard of Protected Mode.

Absolutely. <snip> They have no idea that IE8 running in Protected Mode on Windows 7 is the most secure browser in the world.

Edited by Rob2687
No OS trolling

Absolutely.<snip> They have no idea that IE8 running in Protected Mode on Windows 7 is the most secure browser in the world.

Protected Mode is useless when it gets bypassed. This affects other Windows components, not Internet Explorer itself.

"most superior PC operating system on the planet", "most secure browser in the world", so many tiles... :)

Edited by Rob2687

Protected Mode is useless when it gets bypassed. This affects other Windows components, not Internet Explorer itself.

I have never heard someone getting affected with a malware which managed to bypass Protected Mode, let alone get affected myself. Can you give an example of a known Protected Mode exploit?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The quantum search for Time's origin had an equally mind-boggling conclusion by Sayan Sen Image by Steve Johnson via Pexels A theoretical study from researchers at the University of Surrey suggested that the direction of time may not be fundamentally fixed in certain quantum systems. The work, published in Scientific Reports, examined how the “arrow of time” could emerge from microscopic physics and found that time-reversal symmetry can remain intact even in models used to describe processes such as energy loss and thermalisation. The arrow of time refers to the observed one-way direction from past to future in everyday life. In macroscopic processes, this is easy to see. Spilled milk spreads across a table and does not gather back into a glass, and heat flows from hotter objects to colder ones. These processes shape the common sense idea that time moves in a single direction. However, at the level of fundamental physics, many equations do not prefer a direction of time. Time-reversal symmetry means that the same physical laws can describe a system whether time moves forward or backward. This has made it difficult to explain why irreversible behaviour appears in the large-scale world even when the underlying rules do not require it. Dr Andrea Rocco, Associate Professor in Physics and Mathematical Biology at the University of Surrey, described this contrast: "One way to explain this is when you look at a process like spilt milk spreading across a table, it's clear that time is moving forward. But if you were to play that in reverse, like a movie, you'd immediately know something was wrong – it would be hard to believe milk could just gather back into a glass. However, there are processes, such as the motion of a pendulum, that look just as believable in reverse. The puzzle is that, at the most fundamental level, the laws of physics resemble the pendulum; they do not account for irreversible processes. Our findings suggest that while our common experience tells us that time only moves one way, we are just unaware that the opposite direction would have been equally possible." The study focused on open quantum systems, which are quantum systems that interact with a surrounding environment. This environment, often described as a heat bath, can exchange energy and information with the system. The researchers used this framework to study how a direction of time might appear even when the underlying physics does not enforce one. A key part of the analysis involved the Markov approximation. This is a simplification used in many models where the system is assumed not to retain memory of its past states. The idea is that changes depend only on the current state, not on earlier history. This is commonly used when studying thermalisation, which is the process where a system settles into equilibrium with its environment. The study also used concepts such as master equations, including the Lindblad and Pauli equations, which describe how probabilities of different quantum states change over time. Another related model discussed was quantum Brownian motion, which describes the random-like movement of a quantum particle interacting continuously with its environment. In these descriptions, a “memory kernel” can appear, which is a mathematical term that accounts for how past states influence current behaviour. The researchers found that applying the Markov approximation did not break time-reversal symmetry. Even when the system interacted with an effectively infinite heat bath, the resulting equations of motion remained symmetric in time. This meant that the same mathematical description could, in principle, run forward or backward in time without contradiction. The study further showed that standard frameworks used in open quantum systems, including quantum Brownian motion and master equations like the Lindblad and Pauli forms, could be written in a time-symmetric way. These equations are typically used to describe processes that look irreversible, such as dissipation and thermalisation, but the results suggested they can also be interpreted as allowing evolution in both time directions. Thomas Guff, Research Fellow in Quantum Thermodynamics, said: "The surprising part of this project was that even after making the standard simplifying assumption to our equations describing open quantum systems, the equations still behaved the same way whether the system was moving forwards or backwards in time. When we carefully worked through the maths, we found that this behaviour had to be the case because a key part of the equation, the "memory kernel," is symmetrical in time. We also found a small but important detail which is usually overlooked – a time discontinuous factor emerged that kept the time-symmetry property intact. It’s unusual to see such a mathematical mechanism in a physics equation because it's not continuous, and it was very surprising to see it appear so naturally." The researchers also noted that deriving a one-way arrow of time from time-reversal symmetric microscopic dynamics remains an open problem across fields such as thermodynamics, statistical mechanics, particle physics, and cosmology. Their results suggested that some standard descriptions of irreversible behaviour in open quantum systems may be better understood using a time-symmetric formulation of Markovianity. According to the study, processes such as thermalisation, which are usually treated as irreversible, could in theory be described in a way that allows evolution in either time direction under the same rules. This does not imply that time reversal occurs in everyday life, but rather that the underlying equations do not strictly enforce a single direction. Overall, the findings suggested that the perceived direction of time may emerge from how physical systems are modelled and approximated, rather than from a fundamental asymmetry in the laws themselves. The researchers noted that this perspective could have implications for ongoing work in quantum mechanics, thermodynamics, and cosmology on the origin of time’s arrow. Source: University of Surrey, Nature This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing
    • A bit premature... 100% Marketing. Bizarre.
    • A $300 price hike is insane! No one is going to want to pay that much!
    • Since the 1st one flopped, there is really no reason to make another one. It's just losing money left and right.
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      580
    2. 2
      +Edouard
      182
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      71
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!