Posts Tagged ‘Alert’

What’s old is new again

Yes­ter­day, Mic­ro­soft put out an advi­sory to a secu­rity vul­ne­ra­bi­lity spe­ci­fic to the Win­dows Vista, Win­dows Ser­ver 2008 SP2, and Win­dows 7 RC ope­ra­ting sys­tems.  No other Win­dows ope­ra­ting sys­tems, inc­lu­ding Win­dows 7 RTM are impacted.

Holy cow, once again the older sys­tems (you go XP) are more secure then the new sys­tems.  Why is that you say?  Well this exploit was first found a decade ago.  Yes, you did read that correct, in 1999 this was dis­co­ve­red and patched for the ope­ra­ting sys­tems at the time.  Yet no one thought to put that into the: Newest, Most Secure, Latest and Grea­test ope­ra­ting systems.

So what is this vulnerability?

Accor­ding to Microsoft:

What might an attac­ker use this vul­ne­ra­bi­lity to do?
An attac­ker who suc­cess­fully exploi­ted this vul­ne­ra­bi­lity could take com­plete con­trol of an affec­ted sys­tem. Most attempts to exploit this vul­ne­ra­bi­lity will cause an affec­ted sys­tem to stop res­pon­ding and restart.

I like the last four words, “stop res­pon­ding and res­tart”.  We had an acronym for that back in the day.  BSOD.  But out of all of this, the thing that bothers me the most is Microsoft’s response:

Mic­ro­soft is con­cer­ned that this new report of a vul­ne­ra­bi­lity was not res­pon­sibly disc­lo­sed, poten­tially put­ting com­pu­ter users at risk. We con­ti­nue to encou­rage res­pon­si­ble disc­lo­sure of vul­ne­ra­bi­li­ties. We believe the com­monly accep­ted prac­tice of repor­ting vul­ne­ra­bi­li­ties directly to a ven­dor ser­ves everyone’s best inte­rests. This prac­tice helps to ensure that cus­to­mers receive com­prehen­sive, high-quality upda­tes for secu­rity vul­ne­ra­bi­li­ties without expo­sure to mali­cious attac­kers while the update is being developed.

Mic­ro­soft is con­cer­ned that this new report of a vul­ne­ra­bi­lity was not res­pon­sibly disc­lo­sed? Excuse me what?  It’s not new, it was disc­lo­sed pro­perly the first time.  Why do others become res­pon­si­ble for your oversight?

With that said Mic­ro­soft has issued two do it your­self reso­lu­tions until they can get a patch pushed.

The first is to Disa­ble SMB2 in the registry:

Impact of wor­ka­round. Host will not be able to com­mu­ni­cate using SMB2.

  1. Click Start, click Run, type Rege­dit in the Open box, and then click OK.
  2. Locate and then click the follo­wing registry sub­key:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
  3. Click Lan­man­Ser­ver.
  4. Click Para­me­ters.
  5. Right-click to add a new DWORD (32 bit) Value.
  6. Enter smb2 in the Name data field, and change the Value data field to 0.
  7. Exit.
  8. Res­tart the “Ser­ver” ser­vice by per­for­ming one of the following:
    • Open up the com­pu­ter mana­ge­ment MMC, navi­gate to Ser­vi­ces and Appli­ca­tions, click Ser­vi­ces, right-click the Ser­ver ser­vice name and click Res­tart. Ans­wer Yes in the pop-up menu.
    • From a com­mand prompt and with admi­nis­tra­tor pri­vi­le­ges, type net stop ser­ver and then net start ser­ver.

The second is to Block TCP ports 139 and 445 at the firewall:

Impact of Wor­ka­round: Seve­ral Win­dows ser­vi­ces use the affec­ted ports. Bloc­king con­nec­ti­vity to the ports may cause various appli­ca­tions or ser­vi­ces to not func­tion. Some of the appli­ca­tions or ser­vi­ces that could be impac­ted are lis­ted below:

  • Appli­ca­tions that use SMB (CIFS)
  • Appli­ca­tions that use mails­lots or named pipes (RPC over SMB)
  • Ser­ver (File and Print Sharing)
  • Group Policy
  • Net Logon
  • Dis­tri­bu­ted File Sys­tem (DFS)
  • Ter­mi­nal Ser­ver Licensing
  • Print Spoo­ler
  • Com­pu­ter Browser
  • Remote Pro­ce­dure Call Locator
  • Fax Ser­vice
  • Inde­xing Service
  • Per­for­mance Logs and Alerts
  • Sys­tems Mana­ge­ment Server
  • License Log­ging Service

Per­so­nally, I would block those on your inter­net facing fire­wall of you broad­band router.

1 comment - What do you think?  Posted by Diego - September 10, 2009 at 8:43 am

Categories: Windows   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

When is an antivirus really a virus?

Today I recei­ved a call from one of my exter­nal users that was una­ble to access any web­si­tes because some new anti­vi­rus was saying he was unpro­tec­ted and every web­site had mali­cious code.

Since I know that we have McA­fee 8.5 deplo­yed to our users, I knew that this was not a McA­fee issue.  As we dis­cus­sed it a little further he was men­tio­ning that the Anti­vi­rus wan­ted him to purchase the software.

This isn’t the first I have heard of this.  There is a soft­ware com­pany Inno­va­gest 2000 that is pro­du­cing this soft­ware.  They adver­tise it as an antispy­ware appli­ca­tion, but it is the spy­ware.  On some less then savory web­si­tes you will get a pop up that says that your com­pu­ter maybe infec­ted and they offer a free scan.

The fear of being infec­ted moti­va­tes a lot of peo­ple to run this free scan.  Unk­nown to them this appli­ca­tion ins­talls under­neath and now you are stuck.  On that note, I do recom­mend only doing the online scans from repu­ta­ble sites.  I per­so­nally recom­mend the follo­wing: Syman­tec, Panda, and McA­fee.

This appli­ca­tion is extre­mely hard to get rid of.  It rere­gis­ters and ins­talls if it is not com­ple­tely unins­ta­lled correctly.

I hate pro­grams like this.  But it is a fact of life out there.  The modern day snake-oil salesman.

While the pro­gram is run­ning you will see the follo­wing unde­si­ra­ble behavior:

  • A “Win­dows Secu­rity Cen­ter” sta­ting that you should purchase Per­so­nal Antivirus.
  • Nume­rous alerts sta­ting that your com­pu­ter is under attack or that you have mal­ware run­ning on your com­pu­ter. If you click on these alerts, Per­so­nal Anti­vi­rus will be ins­ta­lled, or you will be brought to the purchase page for the program.
  • Your Inter­net Explo­rer brow­ser will be hijac­ked to show secu­rity war­nings when brow­sing the web that stop you from reaching your desi­red page.

As I men­tio­ned before this bug­ger is very hard to get rid off.  But not impos­si­ble.  I found these ins­truc­tions at BleepingComputer.com.

Read more…

5 comments - What do you think?  Posted by Diego - July 3, 2009 at 11:38 am

Categories: Malware   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Malware Alert — Yellowsn0w

Atten­tion iPhone Users

ZDNet News is repor­ting the follo­wing Alert for iPhone Users:

Researchers from Malware-database.net are repor­ting on a newly dis­co­ve­red mal­ware posing as a bogus iPhone unloc­ker, pro­mi­sing a wor­king Firm­ware 2.2.1 yellowsn0w exploit as a social engi­nee­ring tactic.

If you have an iPhone and are loo­king to unlock your device, please be aware of  this alert.  If you find a site that offers this file, please leave the site imme­dia­tely and per­form a virus scan.  The last known address of the site yellowsn0w221.wordpress.com (now down) was full of viru­ses gea­red to turn your PC into a spambot.

Thanks to Dev-Team Blog for the information.

Be the first to comment - What do you think?  Posted by Diego - June 9, 2009 at 3:32 pm

Categories: Malware   Tags: , , , , , , , , , , , ,

8 visitors online now
8 guests, 0 members
Max visitors today: 10 at 05:05 am CST
This month: 16 at 03-05-2010 08:37 am CST
This year: 19 at 02-08-2010 05:10 am CST
All time: 21 at 12-18-2009 02:01 am CST