This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Ms04-028 Exploits Released!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.php?date=2004-09-23
Updated September 23rd 2004 16:30 UTC
"This is a preliminary diary, and will be updated throughout the day, as the situation warrants, due to the possibility of a rapidly emerging exploit, or worm, we are releasing this early.

Over the last 24hrs, several exploits taking advantage of the JPEG GDI vulnerability (MS04-028) have been released. We expect a rapid developemnt of additional exploits over the next few days. Tom Liston has put together a scanner, which will scan your systems for vulnerable versions of the GDI libraries you can get it at:
- http://isc.sans.org/gdiscan.php
This program should have an MD5 checksum of (91ff45c6158e77eb57fbf6fbe38f05d1). Several non-microsoft programs include versions of GDI libraries which are vulnerable to exploitation. Using this tool you can identify programs which may be vulnerable, and attempt to obtain updates from the software developer…"

.
FYI…

- http://www.techweb.com/article/printableAr…_section=700028
September 24, 2004
"A tool that makes it easy to craft malicious JPEG images then let them loose against vulnerable Windows PCs has appeared, security experts said Friday, leading many to believe an MSBlast-style attack may not be far in the future…Panda Software…said that the tool was a solid clue that a worm exploiting the vulnerability was "imminent"…With a worm and full-scale attack looming, users should patch vulnerable systems immediately. Windows and numerous applications are vulnerable…"
- http://www.pandasoftware.com/about/press/v…px?noticia=5494

:ph34r: :ph34r: :ph34r:
FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.php?date=2004-09-26
Updated September 27th 2004 13:11 UTC
"GDI Vulnerabilities: An open letter to Microsoft

Dear Redmond Folks:

…MS04-028 is, perhaps, the epitome of bad technical writing – the literary equivalent of spaghetti code. I’ve read through it far too many times, and I still understand far too little. Your “GDI Scanning Tool” is worse than useless. Run it, and it tells you that you "may be vulnerable", and directs you to Windows Update and Office Update. Go to Windows Update and update everything you can find. Go to Office Update and do the same. Run the scanner again, and it tells you that you "may be vulnerable", and directs you to Windows Update and Office Update. Lather, rinse, repeat. [Which is why the ISC has made GDIScan.exe and GDICLScan.exe available. See http://isc.sans.org/gdiscan.php for details.]

What about those old gdiplus.dll files that we’re all finding in our Side-By-Side DLL directories? Are they a problem? Why are you updating sxs.dll? Is there vulnerable code in there, or did you just rig it to avoid using the bad code in older versions of gdiplus.dll? (Hey, if you had asked me years ago, I would have told you that this was a serious problem with your Side-By-Side implementation.) When a third party vendor wants to distribute a Microsoft DLL with their product, don’t they have to get permission from you? Wouldn’t there be a list somewhere in Redmond of the third party applications that have distributed vulnerable copies of gdiplus.dll? Can you tell us what they are?

Please stop treating your customers like idiots and give us information; information that we can use. In other words: Turn on the lights and open the door. We’re ready to come back upstairs now.

-TL "


(I don't think it's possible to improve on that…well said, Tom!)
FYI…

JPEG Exploit Hits Usenet, Worm Close Behind
- http://www.techweb.com/article/printableAr…_section=700028
September 28, 2004
"An exploit attacking the most recent Windows bug is circulating on Usenet, security experts said Tuesday, that crashes machines, yet another indicator that attackers will chase the vulnerability until they've launched mass mailing-style worm-based attacks. According to the Bugtraq security mailing list, malicious JPEG images have been posted to several adult newsgroups on Usenet. When viewed, these JPEG images crash unpatched Windows XP and Windows 2000 PCs, said the Internet Storm Center in an online advisory. The images tried to download a backdoor Trojan to the victim systems, but were so poorly coded that all that they did was cause a crash…"
- http://isc.sans.org/diary.php?date=2004-09-27
MS04-028 Public Exploit Attempts…

.
FYI…

New Phishing System Takes Advantage of JPEG Bug
- http://www.eweek.com/print_article/0,1761,a=136324,00.asp
October 1, 2004
"Symantec Corp.'s Threat Analyst Team has discovered an exploit in the wild that utilizes the recently announced JPEG vulnerability in Microsoft Corp.'s GDI+ library to install a new and sophisticated phishing system. eWEEK.com spoke with Oliver Friedrichs, senior manager of Symantec Security Response, who said the infected image is not able to attack a system from within Internet Explorer or Outlook, but only from within Windows Explorer, the file system browsing utility. Therefore, an attacker would likely need to entice a user to view the file from within the file system. This was the most feared scenario for this vulnerability. Because of the nature of this particular attack, as a heap-based integer underflow vulnerability, implementations of the attack are likely to be specific to the application, perhaps even versions of the application, in which the image is viewed. Friedrichs says that it may not be possible to exploit the vulnerability from within Outlook or Outlook Express…

The message itself is a phishing message appearing to come from Citibank and asking the user to go to a specified Web site to confirm personal data or else, so the message claims, access to the user's account will be blocked. The body of the message itself is not text, but an image map, presumably to make it more difficult for counter-measures to work. Instead of scanning for text in the message, patterns in or checksums of the image will have to be employed, although these are often easily defeated with slight randomization of the body of the image. If the user clicks on the link portion of the image, he or she is brought to a Web page residing on a system belonging to a Comcast user. The page brings up a browser window in the background with the actual Citibank home page to give the appearance of legitimacy and a popup in the foreground belonging to the attacker. The popup requests personal information…Symantec believes that the attackers were not novices and had prepared this phishing system in advance, waiting for a suitable vulnerability to come along and be used as a hook for installing the phishing attack. The sophisticated multistage attack will likely reappear in improved form as the attackers learn from their experience with it."
FYI…

- http://www.eweek.com/print_article/0,1761,a=136026,00.asp
By Larry Seltzer - eWeek
"…As Tom Liston pointed out in an open letter to Microsoft, the company's scanning tool for vulnerable programs takes a very narrow view of the problem. It doesn't look generically for the problem. I myself found a better scanning tool;
I call it "DIR C:\GDIPLUS.DLL /S" …It finds all copies of GDIPLUS.DLL on the system and displays their dates.

The file date isn't a guarantee that a file is or isn't vulnerable, and I don't know if you can just copy new, fixed versions to the locations of the vulnerable ones.

Unlike with a browser or e-mail client, most third-party GDIPLUS programs don't work with arbitrary images from arbitrary sources (this is my guess, but I feel good about it). So how do you get the exploit to the images that third-party applications use?

The answer is expensive in terms of network and CPU time, but what's a worm to do other than propagate itself? The worm needs to search out on the computer on which it's running and the network to which it is attached for JPEG files and modify them to include the exploit. This would require the user of the exploited computer to have write privileges to these files, and it would probably leave an audit trail of the modification, but who cares? It's the user of the computer, not the author of the worm, who gets in trouble…"

.
FYI…

- http://isc.sans.org/diary.php?date=2004-10-07
Updated October 8th 2004 07:09 UTC
"…Vulnerable GDI dlls in unexpected places
One writer sent in:
I downloaded the GDI+ detection-tool from <http://isc.sans.org/gdiscan.php> and it reported a vulnerable file:

Directory of C:\Program Files\Microsoft Works 06/20/2002 03:23 AM 1,708,036 gdiplus.dll - Compare to the "patched" file, in other folders: 08/04/2004 12:56 AM 1,712,128 gdiplus.dll

Microsoft Works 7, rather than Microsoft Office, is installed.

The Microsoft detection-tool did *NOT* identify that "Microsoft Works 7" has this vulnerability. D'oh! The Microsoft "home-page" for MS Works does not document this vulnerability. D'oh!

So, it's time to check all your associates' computers, looking to patch this vulnerability within that software, because Microsoft is doing a sloppy job of identifying this vulnerability. Thanks for that tasty tidbit!…"

:ph34r:
FYI…

Security Update for JPEG Processing (GDI+)
- http://www.microsoft.com/security/bulletins/200409_jpeg.mspx
Updated: October 12, 2004 <<<
"…Microsoft Security Bulletin MS04-028 was re-released on October 12, 2004, to address an issue that prevented some updates originally released on September 14, 2004, from installing on computers running Windows XP SP2. If you use Windows XP SP2 and if you installed the original updates for Visio 2002, Project 2002, or Office XP, you should return to the Office Update Web site to install the revised updates…"
- http://office.microsoft.com/en-us/officeupdate/default.aspx

.
FYI…

- http://www.us-cert.gov/cas/bulletins/SB04-…html#jpegbuffer
Summary of Security Items from October 6 through October 12, 2004
"A buffer overflow vulnerability exists in the processing of JPEG image formats, which could let a remote malicious user execute arbitrary code. Frequently asked questions regarding this vulnerability and the patch can be found at: - http://www.microsoft.com/technet/security/…n/ms04-028.mspx

Another exploit script has been published.

Vendor & Software Name
Microsoft .NET Framework 1.x, Digital Image Pro 7.x, 9.x, Digital Image Suite 9.x, Frontpage 2002, Greetings 2002, Internet Explorer 6, Office 2003 Professional Edition, 2003 Small Business Edition, 2003 Standard Edition, 2003 Student and Teacher Edition, Office XP, Outlook 2002, 2003, Picture It! 2002, 7.x, 9.x, PowerPoint 2002, Producer for Microsoft Office PowerPoint 2003, Project 2002, 2003, Publisher 2002, Visio 2002, 2003, Visual Studio .NET 2002, 2003, Word 2002; Avaya DefinityOne Media Servers, IP600 Media Servers, S3400 Modular Messaging, S8100 Media Servers

Microsoft JPEG Processing Buffer Overflow - CVE Name: CAN-2004-0200"