New User, Welcome!     Login

Next Page >>

shell extension

Using Blended Browser Threats involving Chrome to steal files on your computer

The vulnerability arises from the fact that there are other extensions such
as .svg, .mht, .mhtml that don't exist in the Chrome's malicious extension
blacklist and hence the user never gets a warning message before they are
auto downloaded to his or her computer. If these downloaded files are
clicked from the Chrome's download bar or Windows Explorer (which the user
is highely likely to click considering his or her trust in Chrome that it
warns for malicious extensions), they will automatically get opened in other
browsers and can be used to steal any file on the user's computer.

The reason for the name "Blended Browser Threats" is because here, Google

[security bulletin] HPSBMA02491 SSRT100060 rev.1 - HP Operations Manager for Windows, Remote Execution of Arbitrary Code

1. Stop the Operations Manager for Windows console and its additional binaries, such as node editor.
2. From a command prompt, backup %OvInstallDir%\bin\srcvw4.dll
3. From a command prompt, copy OMW60_srcvw4.dll into %OvInstallDir%\bin\srcvw4.dll
4. Verify that %OvInstallDir%\bin\srcvw4.dll is now v4.0.1.2

Note: Steps 2 and 3 above must be performed from the Windows command line, not from Windows Explorer.

For Operations Manager for Windows v7.5

Verify the version of srcvw32.dll currently installed


RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities

Internet Video Recording (IVR) files contain media content that is played and recorded by RealPlayer. A remote attacker could craft a malicious IVR file, that when sent to an unsuspecting user, may allow the execution of arbitrary code when viewed, using one of two vulnerabilities during RealPlayer's IVR processing routine:

    * A heap corruption vulnerability that occurs when altering a field that determines the length of a structure
    * A vulnerability that allows an attacker to write one null byte to an arbitrary memory address by using an overly long file name length value

It should be noted that the victim does not necessarily have to open the malicious file for exploitation to occur: the vulnerabilities lie in a DLL that is also used as a plugin for the Windows Explorer shell. A successful attack could take place by merely previewing the IVR file through Windows Explorer.

Solutions:
==========

The FortiGuard Global Security Research Team released the signature "RealNetworks.RealPlayer.IVR.File.Processing.Code.Execution"

ICQ 6.5 URL Search Hook/ICQToolBar.dll .URL file processing Windows Explorer remote buffer overflow poc

If the resulting file is placed on the desktop, against ex. xp sp3
process explorer.exe will exit with code 1282 (0x502) that is
ERROR_STACK_BUFFER_OVERRUN and crash infinitely, you cannot even browse a folder
if the file is present in it
Solution: disable the shell extension, you may try shellexview by nirsoft

Note (added 30/05/2009, remote vector added): it works with network folders
too ...

against a win2k3 where explorer.exe is not patched with /GS flag:

n.runs-SA-2009.005 - Apple Safari - Information disclosure

Description:

Passing the file protocol handler to a certain HTML allows to read local 
files. 
On Windows it is possible to create an instance of Windows Explorer by 
calling an executable file. Other operating systems were not tested.  


In detail, the following flaw was determined:


Re: At long last -- Extra Outlooks!

 > running in the same interactive logon space, and when it starts, it just
 > calls another popup in the previous Outlook space and then terminates
 > itself (that's close enough, anyway). The good news is that there is no
 > "user hopping" or "boundary crossing" here. 

Sounds comparable to what the Windows Explorer does when 
it is not expicitly set to run as a separate process (or 
started with the /separate switch).

Is there some design principle behind this kind of behaviour?


CORE-2008-0103: Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass

where X is an integer like 1,2,3, depending on the Internet Explorer
choice.

The cookies folder is hardcoded inside the Explorer engine as a
restricted site. You can check it by looking at the status bar when
browsing this folder with Windows Explorer.

When requesting a resource, for example, in the 'src' attribute of an
HTML 'img' tag, Internet Explorer allows the usage of 'smb' URIs. So,
when IE attempts to render the following line:


Re: At long last -- Extra Outlooks!

> > running in the same interactive logon space, and when it starts, it just
> > calls another popup in the previous Outlook space and then terminates
> > itself (that's close enough, anyway). The good news is that there is no
> > "user hopping" or "boundary crossing" here. 
>
>Sounds comparable to what the Windows Explorer does when 
>it is not expicitly set to run as a separate process (or 
>started with the /separate switch).


Or what firefox, mozilla and other do when you start them on the command 

Re: Confirmed: Windows Explorer bad PNG file preview integer overflow handling

Problem confirmed on multiple Windows Explorer releases and also reproduced on antivirus softwares (same infinite loop consumming 100% CPU).



iDefense Security Advisory 01.12.10: Adobe Reader and Acrobat JpxDecode Memory Corruption Vulnerability

can reduce potential attack vectors and make exploitation more
difficult.

Prevent PDF documents from being opened automatically by the Web browser
Disable JavaScript
Disable PDFShell extension by removing or renaming the Acrord32info.exe file

VI. VENDOR RESPONSE

Adobe has released a patch which addresses this issue. Information about
downloadable vendor updates can be found by clicking on the URLs shown.

CORE-2009-0911: DAZ Studio Arbitrary Command Execution

The vendor did not provide fixes or workaround information.

To prevent the accidental execution of malicious scripting files you
can disable the default file association of the dangerous file
extensions in the Windows Explorer. The following KB article from
Microsoft describe how to deassociate a file extension.
http://support.microsoft.com/kb/307859


6. *Credits*

RE: At long last -- Extra Outlooks!

>  > itself (that's close enough, anyway). The good news is that there
is
> no
>  > "user hopping" or "boundary crossing" here.
> 
> Sounds comparable to what the Windows Explorer does when
> it is not expicitly set to run as a separate process (or
> started with the /separate switch).
> 
> Is there some design principle behind this kind of behaviour?
> 

iDefense Security Advisory 06.11.09: Adobe Reader and Acrobat FlateDecode Integer Overflow Vulnerability

victim to open it. This can be accomplished by embedding the PDF file
into an IFRAME inside of a Web page, which will result in automatic
exploitation once the page is viewed. The file could also be e-mailed
as an attachment or placed on a file share. In these cases, a user
would have to manually open the file to trigger exploitation. If
preview is enable in Windows Explorer, this vulnerability can be
triggered simply by accessing a folder containing PDF files.

IV. DETECTION

Acrobat Reader and Acrobat Professional versions 7.1.0, 8.1.3, 9.0.0 and

iDefense Security Advisory 12.11.07: Microsoft DirectX 7 and 8 DirectShow Stack Buffer Overflow Vulnerability

It is important to note that a SAMI file does not necessarily have to
end with a .smi or .sami extension. DirectShow will identify the file
based on the file contents.

If "Web View Content" is enabled in Windows Explorer, which is the
default setting, a single click will open the malicious file in the
preview pane and trigger the vulnerability.

DirectX 9.0c is listed as an optional update for Windows 2000 operating
system in Windows Update site. It is not listed as a critical update.

Re: At long last -- Extra Outlooks!

>  > calls another popup in the previous Outlook space and then terminates
>  > itself (that's close enough, anyway). The good news is that there is 
no
>  > "user hopping" or "boundary crossing" here. 
> 
> Sounds comparable to what the Windows Explorer does when 
> it is not expicitly set to run as a separate process (or 
> started with the /separate switch).
> 
> Is there some design principle behind this kind of behaviour?
> 

CORE-2008-0826 - Internet Explorer Security Zone restrictions bypass

located at: 'C:\Documents and settings\USERNAME\Local
settings\History\History.IE5\index.dat'. Although the format of this
file is not entirely text, IE will store every visited URL including any
parameters in the query string in plain text.
   2. Although the aforementioned folder cannot be directly browsed
using Windows Explorer or Internet Explorer, it can be browsed and
viewed by referring to the same folder using the UNC notation:
'\\[COMPUTERNAME|127.0.0.1]\C$\Documents and settings\USERNAME\Local
settings\History\History.IE5'.
   3. There are some HTML tags which allow to embed contents from
external files and treat them with a specific format disregarding the

CA ARCserve Backup LDBserver Vulnerability

Alternatively, use the file information below to determine if the 
product installation is vulnerable.

CA ARCserve Backup r11.1 Windows:

1. Using Windows Explorer, locate the file "DBserver.dll". By 
   default, the file is located in the 
   "C:\Program Files\CA\BrightStor ARCserve Backup" directory.

2. Right click on the file and select Properties.


CA Host-Based Intrusion Prevention System SDK kmxfw.sys Multiple Vulnerabilities

version number is 1.2.276 or higher. For support information, 
visit http://shop.ca.com/support.


How to determine if you are affected:
1. Using Windows Explorer, locate the file "kmxfw.sys". By default, 
   the file is located in the "C:\Windows\system32\drivers\" directory.
2. Right click on the file and select Properties.
3. Select the General tab.
4. If the file version is less than indicated in the below table, 
   the installation is vulnerable.

[CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities

   latest patches.
BrightStor ARCserve Backup v9.01 - QO91098
CA Protection Suites r2 - QO91094

How to determine if you are affected:
1. Using Windows Explorer, locate the file “mediasvr.exe”. By 
   default, the file is located in the 
   “C:\Program Files\CA\BrightStor ARCserve Backup” directory.
2. Right click on the file and select Properties.
3. Select the General tab.
4. If the file timestamp is earlier than indicated in the table 

[CAID 35673, 35674, 35675, 35676, 35677]: CA ARCserve Backup for Laptops and Desktops Multiple Server Vulnerabilities

CA Desktop Management Suite 11.2 localized:
Apply QO91111.

How to determine if you are affected:
For Windows:
1. Using Windows Explorer, locate the file "rxRPC.dll". The file 
can be found in the following default locations:

Products \ Directory Paths
--------------------------
CA ARCserve Backup for Laptops and Desktops 11.5 

CA20090806-01: Security Notice for Data Transport Services

How to determine if the installation is affected

For Windows:

1. Using Windows Explorer, locate the file indicated in the below
table. By default, the file can be found in the following locations:

Product
File
Directory Path

CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)

&searchID=RO04648


How to determine if you are affected:

1. Using Windows Explorer, locate the file "RELEASE-NOTES".
2. By default, the file is located in the 
   "C:\Program Files\CA\Cohesion\Server\server\" directory.
3. Open the file with a text editor.
4. If the version is less than 5.5.25, the installation is 
   vulnerable.

CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities

&searchID=RO04648


How to determine if you are affected:

1. Using Windows Explorer, locate the file "RELEASE-NOTES".
2. By default, the file is located in the 
   "C:\Program Files\CA\Cohesion\Server\server\" directory.
3. Open the file with a text editor.
4. If the version is less than 5.5.25, the installation is 
   vulnerable.

CA20090818-01: Security Notice for CA Host-Based Intrusion Prevention System

CA Host-Based Intrusion Prevention System 8.1 CF 1

How to determine if the installation is affected

1. Using Windows Explorer, locate the file "kmxIds.sys". By
default, the file is located in the
"C:\Windows\system32\drivers\" directory.
2. Right click on the file and select Properties.
3. Select the Version tab.
4. If the file version is less than indicated in the below table, the

CA ARCserve Backup Discovery Service Denial of Service Vulnerability

CA ARCserve Backup r11.5 Windows,
CA ARCserve Backup r11.1 Windows,
CA ARCserve Backup r11.1 Netware,
CA Protection Suites r2*:

1. Using Windows Explorer, locate the file “asbrdcst.dll”. By 
   default, the file is located in the 
   “C:\Program Files\CA\SharedComponents\ARCserve Backup\CADS” 
   directory on 32 bit systems and “C:\Program Files (x86)\CA\
   SharedComponents\ARCserve Backup\CADS” on 64 bit systems.
2. Right click on the file and select Properties.

CA ARCserve Backup caloggerd and xdr Functions Vulnerabilities

How to determine if you are affected:

For Windows:

   1. Using Windows Explorer, locate the file "caloggerd.exe". By 
      default, the file is located in the 
      "C:\Program Files\CA\BrightStor ARCserve Backup" directory.

   2. Right click on the file and select Properties.


CA20091008-01: Security Notice for CA Anti-Virus Engine

How to determine if the installation is affected

For products on Windows:

1. Using Windows Explorer, locate the file "arclib.dll".  By 
   default, the file is located in the 
   "C:\Program Files\CA\SharedComponents\ScanEngine" directory (*).
2. Right click on the file and select Properties.
3. Select the Version tab.
4. If the file version is earlier than indicated below, the 

CA ARCserve Backup for Laptops and Desktops Server LGServer Service Vulnerability

How to determine if you are affected:

For Windows:

1. Using Windows Explorer, locate the file "rxRPC.dll". The file 
can be found in the following default locations:

   CA ARCserve Backup for Laptops and Desktops 11.5:
   C:\Program Files\CA\BrightStor ARCserve Backup for Laptops and 
      Desktops\Server

CA Multiple Products DSM ListCtrl ActiveX Control Buffer Overflow Vulnerability

Unicenter Remote Control r11.2 C1:
QO96090

How to determine if you are affected:
For products on Windows:
   1. Using Windows Explorer, locate the file "ListCtrl.ocx". By 
      default, the file is in the "C:\Program Files\CA\DSM\bin\" 
      directory.
   2. Right click on the file and select Properties.
   3. Select the Version tab.
   4. If the file version is earlier than indicated in the below 

CA Alert Notification Server Multiple Vulnerabilities

   latest patches.

How to determine if you are affected:

For products on Windows:
   1. Using Windows Explorer, locate the file "alert.exe". By 
      default, the file is located in the 
      "C:\Program Files\CA\SharedComponents\Alert" directory.
   2. Right click on the file and select Properties.
   3. Select the Version tab.
   4. If the file version is earlier than indicated in the below 

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!