1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Lets Paint The Kettle Black,Do You Have A Bitch On Whats Going On Around The Site Or Any Thing Negative To Report

Discussion in 'Safety valve' started by ireland, Mar 28, 2006.

Thread Status:
Not open for further replies.
  1. ireland

    ireland Active member

    Joined:
    Nov 28, 2002
    Messages:
    3,451
    Likes Received:
    15
    Trophy Points:
    68
    Bug affecting IE and Windows is potentially very damaging,


    Common Name:
    Windows .ANI Processing

    Date Disclosed:
    3/28/2007

    Expected Patch Release:
    Unknown

    Vendor:
    Microsoft

    Application:
    Microsoft Windows 2000
    Microsoft Windows XP
    Microsoft Windows Server 2003
    Microsoft Windows Vista


    Description:
    An unspecified vulnerability exists within Microsoft Windows which may possibly allow for a remote attacker to execute arbitrary code under the context of the logged in user. This vulnerability requires user interaction by viewing a malicious Windows animated cursor (.ANI) file. .ANI files are commonly used by web developers to display custom cursor animations to enhance web-site experiences.

    The most potent attack method is by embedding a malicious .ANI file within an HTML web page. Doing so allows the vulnerability to be exploited with minimal user interaction by simply coaxing a user to follow a hyperlink and visit a malicious web site. Other exploit vectors exist including Microsoft Office applications since they also rely on the same .ANI processing code, making e-mail delivery also a potent threat by using Microsoft Office attachments.

    Since .ANI processing is performed by USER32.dll and not the attack vector application itself, all attack vectors have the potential to use a similar exploit with similar address offsets targeted at Windows directly, allowing for a very reliable exploit.

    NOTE: This advisory information is gathered from the references below. eEye Research is currently researching the cause of the vulnerability and trying to identify other vulnerable and will update this ZDT entry as more information becomes available.

    Severity:
    High


    Code Execution:
    Yes



    Impact:
    Arbitrary code execution under the context of the logged in user
    A web browser remote code execution vulnerability has a very high impact since the source of the malicious payload can be any site on the Internet. An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials. Exploitation impact can vary from the reported trojan installation to full system compromise by coupling this attack with a privilege escalation vulnerability to acquire SYSTEM access.

    Mitigation:
    eEye Digital Security's Research Team has released a workaround for the zero-day vulnerability as a temporary measure for customers who have not yet installed Blink. Blink generically protects from this and other vulnerabilities without the need for updating and is available for free for personal use on all affected platforms except for Vista. This workaround is not meant to replace the forthcoming Microsoft patch, but rather as a temporary mitigation against this flaw.

    The temporary patch mitigates this vulnerability by preventing cursors from being loaded outside of %SystemRoot%. This disallows websites from loading their own, potentially malicious animated icons, while causing little to no business disruption on hosts with the patch installed.

    Organizations that choose to employ this workaround should take the steps required to uninstall it once the official Microsoft patch is released. More information regarding installation and uninstallation is available in the patch installer. Please note that at this time this workaround supports all affected platforms except for x64 and Itanium architectures.

    Patch Location: Download Now!
    Patch Version: 1.0

    http://www.eeye.com/html/research/tools/WindowsANIZeroDayPatchSetup.exe

    Patch Source Code: View

    http://research.eeye.com/html/alerts/zeroday/20070328.html
     
  2. blivetNC

    blivetNC Regular member

    Joined:
    Nov 8, 2005
    Messages:
    1,692
    Likes Received:
    0
    Trophy Points:
    46
  3. Domreis

    Domreis Regular member

    Joined:
    May 16, 2005
    Messages:
    3,086
    Likes Received:
    0
    Trophy Points:
    46
  4. blivetNC

    blivetNC Regular member

    Joined:
    Nov 8, 2005
    Messages:
    1,692
    Likes Received:
    0
    Trophy Points:
    46
    I know, and just for the sake of a few L.E.D.'s?
     
  5. fortunat1

    fortunat1 Member

    Joined:
    Mar 31, 2007
    Messages:
    0
    Likes Received:
    0
    Trophy Points:
    10
    I don't smoke the ciggies but a peace pipe. you guys all are a bunch of knots. Give up that crap!
     
  6. blivetNC

    blivetNC Regular member

    Joined:
    Nov 8, 2005
    Messages:
    1,692
    Likes Received:
    0
    Trophy Points:
    46
    @fortunat1,
    ????????????
     
  7. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,165
    Likes Received:
    136
    Trophy Points:
    143
    blivetNC, 2nd that!!
     
  8. garmoon

    garmoon Regular member

    Joined:
    Oct 7, 2004
    Messages:
    3,971
    Likes Received:
    0
    Trophy Points:
    46
    Must be smoking crack in that peace pipe!
     
  9. aabbccdd

    aabbccdd Guest

    damn no more RipIt4Me its gone finshed out of here .all links are dead on the web
     
  10. ireland

    ireland Active member

    Joined:
    Nov 28, 2002
    Messages:
    3,451
    Likes Received:
    15
    Trophy Points:
    68
  11. blivetNC

    blivetNC Regular member

    Joined:
    Nov 8, 2005
    Messages:
    1,692
    Likes Received:
    0
    Trophy Points:
    46
    @Ireland,
    I am afraid the lamentations are directed at the fact that Ripit4me is no longer being offered by its author(s), which means that there will be no more updates to it, and like Shrink, and DVDdecrypter, will fade away until someone writes another program to get around the new copyright schemes implimented by the mafia.
     
  12. Ripper

    Ripper Active member

    Joined:
    Feb 20, 2006
    Messages:
    4,697
    Likes Received:
    13
    Trophy Points:
    68
    Or we could just get AnyDVD and be happy :p

    [Edit]

    :)
     
    Last edited: Apr 1, 2007
  13. The_Fiend

    The_Fiend Guest

    jackrocks ? little typo, or are you having delusions of grandeur here ?
     
  14. Ripper

    Ripper Active member

    Joined:
    Feb 20, 2006
    Messages:
    4,697
    Likes Received:
    13
    Trophy Points:
    68
    Lmfao!

    Hmm, subconcious typo methinks ;-)

    Oh btw Dan, around on Irc?
     
    Last edited: Apr 1, 2007
  15. Nephilim

    Nephilim Moderator Staff Member

    Joined:
    Feb 13, 2003
    Messages:
    13,161
    Likes Received:
    1
    Trophy Points:
    116
    I have a bitch. I looooove the classic rock stations but they never play anything new. It's always the same old stuff..................................
     
  16. Lp531

    Lp531 Regular member

    Joined:
    Sep 23, 2005
    Messages:
    885
    Likes Received:
    0
    Trophy Points:
    26
    I have been wondering about that same thing...LOL...
     
  17. blivetNC

    blivetNC Regular member

    Joined:
    Nov 8, 2005
    Messages:
    1,692
    Likes Received:
    0
    Trophy Points:
    46
    Someone call 911, Neph has fallen and bumped his head. Remember the glory days of the 70's? When the Album Rock format was the craze? (Don't play the hits, play the obscure stuff from the rest of the album no one remembers or has never heard from a one shot wonder)
    A sure sign of getting OLD Neph, when your kids love a "New" song, only to be informed that someone recorded it back in the 70's as a cover of an old 50's song. Ah the young-un's these days,
     
  18. Nephilim

    Nephilim Moderator Staff Member

    Joined:
    Feb 13, 2003
    Messages:
    13,161
    Likes Received:
    1
    Trophy Points:
    116
    Boy oh boy is that true. I run into a lot of kids these days that are into music but I rarely see one thats into music. A while back when No Doubt did a marginal cover of Talk Talk's early eighties hit "It's My Life" and Iw ondered how many kids liked that song but had no clue about the wonderful and, in their later years, extremely talented band that wrote it. Their later albums like Color of Spring, Spirit of Eden and Laughing Stock are amazing and very original albums but most kiddies will miss out on them.

    Another case in point - A couple years ago on some forum music forum I saw some teenage girl go on and on about Marilyn Manson's pioneering originality in creepy satanic shock rock. All I could do is shake my head. Ever heard of Alice Cooper you dummy? Any idea who King Diamond is? How could you have missed Black Sabbath? You think a half-rate putz like Marilyn Manson thought all that up himself? Not a chance. Different colored contacts and dressing like a trashy man-hooker doesn't make him original.

    Then the same girl went on about how she was such a goth and how Nickelback was such a total goth band (NOT!) and it almost made me puke. I asked her if she listened to Bauhaus and she had no idea who they were. The band that almost singlehandedly shaped the goth movement and she had never heard of them.

    Typically if you take a band you like and trace back their influences you'll find a wealth of phenomenal music you'd have otherwise missed. The reverse holds true too. If you're into an band or artist from a past decade then look at who they've influenced and see what the next generation's done with it.

    Oh well, Sunday rant is over :p

    Take care all :)
     
    Last edited: Apr 1, 2007
  19. LOCOENG

    LOCOENG Moderator Staff Member

    Joined:
    Feb 4, 2005
    Messages:
    10,818
    Likes Received:
    4
    Trophy Points:
    118
    Take away the colored contacts and David Bowie aka Ziggy Stardust had the trashy man-hooker bit down pat long before the rest.
     
  20. The_Fiend

    The_Fiend Guest

    Neph, you forgot to mention Sisters of Mercy ;-)
    And The Damned, but that's excusable :-D
     
Thread Status:
Not open for further replies.

Share This Page