AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-08-18
Updated August 18th 2005 23:39 UTC
Infocon gone Yellow
The Infocon status is now yellow, due to the MSDDS.DLL exploit now available. We moved to Yellow as we feel widespread malicious use of this vulnerability is imminent, and the workarounds shown here provide sufficient countermeasures to be applied quickly. We expect to move back to green by the end of the day or early tomorrow.
Internet Explorer (.Net) 0day msdds.dll Exploit & Patch
Yesterday, FrSIRT (aka K-otik) released a working 0-day exploit against a .Net component with is accessible remotely via Microsoft Internet Explorer.
Update 1600 EST:
http://www.microsoft.com/technet/security/…ory/906267.mspx
Microsoft has released a security advisory with regards to MSDDS.DLL.
Impact
The exploit will open a remote shell if you visit a malicious website. Other payloads are possible. The exploit will have all the privileges assigned to the user running Internet Explorer. We do not see any use of the exploit at this time, but consider widespread use imminent.
Am I Vulnerable?
You are only vulnerable if you have "msdds.dll" installed on your system. By default, Windows will not install this DLL. See below for details. The DLL can be found in Program Files\Common Files\MicrosoftShared\MSDesigners7. Note that the directory may be named differently in non-english versions of Windows.
>>> The vulnerable version is: 7.0.9064.9112 . Later versions are not vulnerable (in particular 7.10.x)
Workarounds
While there are no official patches available, there are a number of workarounds:
* Set "kill bit" for the ActiveX component. We released a number of scripts to set the "kill bit" for the affected ActiveX component. This will prevent use of the vulnerable ActiveX component by Internet Explorer. msdds.dll may still be used by local applications (and this is ok). But this may break activex applications accessed via the browser, if they make use of this vulnerable function. Download the ISC MSDDS Patch.
>>> http://isc.sans.org/msddskillbit.php
* You can make the same change using the registry editor. Change this key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\EC444CB6-3E7E-4865-B1C3- 0DE72EF39B3F\Compatibility Flags=0x00000400" [Jerry] I added a space in the key to avoid the above mentioned content filter rule [John].
* Remove the vulnerable DLL from your system. This may break various applications that installed the DLL.
* Use 'DropMyRights' to limit the impact of an exploit.
* Use an alternative browser (Firefox, Opera) which does not provide ActiveX.
Note that other browsers may in fact use the MSIE engine to render code, for example ActiveX such as this one. Netscape 8 for example has this capability, and may be vulnerable. This has not yet been confirmed…
MSDDS Trivia:
- MSDDS stands for "Microsoft Design Tools - Diagram Surface".
- you sometimes may find the (wrong) spelling of msdss in earlier versions of our diaries.
Related Links:
http://secunia.com/advisories/16480/ …"

- http://isc.sans.org/diary.php?date=2005-08-18
Updated August 18th 2005 23:39 UTC
Infocon gone Yellow
The Infocon status is now yellow, due to the MSDDS.DLL exploit now available. We moved to Yellow as we feel widespread malicious use of this vulnerability is imminent, and the workarounds shown here provide sufficient countermeasures to be applied quickly. We expect to move back to green by the end of the day or early tomorrow.
Internet Explorer (.Net) 0day msdds.dll Exploit & Patch
Yesterday, FrSIRT (aka K-otik) released a working 0-day exploit against a .Net component with is accessible remotely via Microsoft Internet Explorer.
Update 1600 EST:
http://www.microsoft.com/technet/security/…ory/906267.mspx
Microsoft has released a security advisory with regards to MSDDS.DLL.
Impact
The exploit will open a remote shell if you visit a malicious website. Other payloads are possible. The exploit will have all the privileges assigned to the user running Internet Explorer. We do not see any use of the exploit at this time, but consider widespread use imminent.
Am I Vulnerable?
You are only vulnerable if you have "msdds.dll" installed on your system. By default, Windows will not install this DLL. See below for details. The DLL can be found in Program Files\Common Files\MicrosoftShared\MSDesigners7. Note that the directory may be named differently in non-english versions of Windows.
>>> The vulnerable version is: 7.0.9064.9112 . Later versions are not vulnerable (in particular 7.10.x)
Workarounds
While there are no official patches available, there are a number of workarounds:
* Set "kill bit" for the ActiveX component. We released a number of scripts to set the "kill bit" for the affected ActiveX component. This will prevent use of the vulnerable ActiveX component by Internet Explorer. msdds.dll may still be used by local applications (and this is ok). But this may break activex applications accessed via the browser, if they make use of this vulnerable function. Download the ISC MSDDS Patch.
>>> http://isc.sans.org/msddskillbit.php
* You can make the same change using the registry editor. Change this key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\EC444CB6-3E7E-4865-B1C3- 0DE72EF39B3F\Compatibility Flags=0x00000400" [Jerry] I added a space in the key to avoid the above mentioned content filter rule [John].
* Remove the vulnerable DLL from your system. This may break various applications that installed the DLL.
* Use 'DropMyRights' to limit the impact of an exploit.
* Use an alternative browser (Firefox, Opera) which does not provide ActiveX.
Note that other browsers may in fact use the MSIE engine to render code, for example ActiveX such as this one. Netscape 8 for example has this capability, and may be vulnerable. This has not yet been confirmed…
MSDDS Trivia:
- MSDDS stands for "Microsoft Design Tools - Diagram Surface".
- you sometimes may find the (wrong) spelling of msdss in earlier versions of our diaries.
Related Links:
http://secunia.com/advisories/16480/ …"