This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

IEv7 0-day exploit in the wild...

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

IE XML processing memory corruption
- http://secunia.com/advisories/33089/
Release Date: 2008-12-10
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x…
…Successful exploitation allows execution of arbitrary code.
NOTE: Reportedly, the vulnerability is currently being actively exploited.
The vulnerability is confirmed in Internet Explorer 7 on a fully patched Windows XP SP3. Other versions may also be affected.
Solution: Do not browse untrusted websites or follow untrusted links.
Provided and/or discovered by: Reported as a 0-day…

- http://isc.sans.org/diary.html?storyid=5458
Last Updated: 2008-12-10 09:38:03 UTC

:ph34r: :ph34r:
FYI…

- http://securitylabs.websense.com/content/Alerts/3259.aspx
12.10.2008 - "…No user interaction is necessary for the exploit to be successful. A computer may become infected by simply visiting a malicious Web site. This vulnerability exists in the way XML is processed within Internet Explorer 7…"

- http://isc.sans.org/diary.html?storyid=5458
Last Updated: 2008-12-11 09:50:54 UTC …(Version: 3) - "…Update: Microsoft published a bulletin regarding this issue*… In addition, shadowserver.org published a list of infected sites**. Note that this list may not be complete. The best mitigating action from the bulletin is probably to enable DEP for Internet Explorer 7…

* http://www.microsoft.com/technet/security/…ory/961051.mspx
December 10, 2008 - "…Suggested Actions… Workarounds:
Microsoft has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they help block known attack vectors…
• Set Internet and Local intranet security zone settings to "High" to prompt before running ActiveX Controls and Active Scripting in these zones…
• Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone…
• Enable DEP for Internet 7…

IE7 0-Day Exploit Sites
** http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081210
10 December 2008 - "…the first step you can take is to block the above domains and/or IP addresses. These sites are for the most part hosting a bunch of bad stuff and not just an IE7 exploit. However, there are certainly sites that we have missed and new ones that will pop up frequently, so this will not stop completely stop it all either. The only other real option against this exploit for now is an obvious one and that's to just not use IE7 until the issue has been resolved…"

> http://isc.sans.org/diary.html?storyid=5458
Last Updated: 2008-12-11 09:50:54 UTC …(Version: 3) - "…UPDATE 2: …we received log files showing that attackers using SQL injection are now. The SQL Injection attacks are similar to those we've described multiple times before (see http://isc.sans.org/diary.html?storyid=4565 , for example). The important part includes the target URL that is injected:
… rtrim(convert(varchar(4000),['+@C+']))+''''')FETCH NEXT FROM …
This domain is not listed by Shadowserver yet. The 1.js script on the domain links to multiple other HTML documents of which one is called ie7.htm … If executed successfully, the script will download the binary from http ://www [dot] steoo [dot] com/admin/win.exe. This is a game password stealer which has sporadic detection ( http://www.virustotal.com/analisis/244ae03…9c50b614fddde6a ) – there are some big names still missing it. In any case, the attackers are picking this quickly so make sure that you are following recommendations from Microsoft's advisory which will help reduce exposure or, if you can, use an alternative browser until this has been fixed."

_____

- http://securitylabs.websense.com/content/Alerts/3260.aspx
12.11.2008 - "Websense… has discovered that the Taiwanese search engine "look.tw" has been compromised and is infecting site visitors with malicious code. The Web site has been injected with a recently announced Internet Explorer 7 Zero Day Attack ( http://securitylabs.websense.com/content/Alerts/3259.aspx ). The exploit on the site attempts to download a malicious excutable called "ieupdate.exe". The download location is currently down, but could come back at any moment."

:ph34r: :ph34r: :ph34r:
FYI…

MSIE 0-day Spreading Via SQL Injection
- http://isc.sans.org/diary.html?storyid=5464
Last Updated: 2008-12-12 01:00:18 UTC

Full list of Injected Sites
- http://www.shadowserver.org/wiki/uploads/C…ql-inj-list.txt
Last Updated: 12/11/08 12:05:32 -0400

IE7 0day expanded to include IE6 and IE8(beta)
- http://isc.sans.org/diary.html?storyid=5470
Last Updated: 2008-12-12 01:26:35 UTC

- http://securitylabs.websense.com/content/alerts.aspx
Date Description
12.12.2008 - Peking University Web Site in China Compromised
12.12.2008 - ABIT China Web site Attacked by IE7 Zero Day
12.11.2008 - Taiwanese Search Engine, Look, Infected with IE 7 Zero Day

- http://www.kb.cert.org/vuls/id/493881
Last Updated: 2008-12-11

:ph34r:
Blocks…

- http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081211
11 December 2008 - "…It turns out the domain that ISC is reported on is also dropping some pretty nasty malware. The domain "17gamo .com" is serving up the exploits which attempt to download malware from "www .steoo .com". Please do not visit either of these sites. If successful the exploits will install a Gh0st RAT on the system. This trojan is currently using the DNS name "evetlog .3322 .org" and is beaconing to tcp port 3020.
We recommend blocking or looking for traffic to all of the sites we list*… but in particular as it related to this threat the following:
www .17gamo .com - [removed]
www .steoo .com - [removed]
evetlog .3322 .org - [removed] (was recently [removed]]
The IP addresses are of course subject to change, so we recommend resolving them when appropriate for traffic monitoring/blocking…."
* http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081210
Updated 12/12/2008 - 14:17 UTC/GMT

:ph34r: :ph34r:
FYI…

IE7 0-Day Exploit Sites
- http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081210
"…Shadowserver is aware of several hosts which are currently hosting exploit code designed to exploit this vulnerability. We would like to share this information so that it can be used for protection and detection. However, we strongly discourage visiting these sites for any reason. DO NOT visit the below sites as they are currently house live exploit code for the new IE7 0day exploit. The majority if not all of them also house several other exploits for different vulnerabilities as well…
vw. wd2a .cn - 218.83.161.134
927 .bigwww .com - 221.10.254.228
h3hs4 .cn - [removed]
…the first step you can take is to block the above domains and/or IP addresses. These sites are for the most part hosting a bunch of bad stuff and not just an IE7 exploit. However, there are certainly sites that we have missed and new ones that will pop up frequently, so this will not stop completely stop it all either. The only other real option against this exploit for now is an obvious one and that's to just not use IE7 until the issue has been resolved…"
Page last modified on December 14, 2008, at 01:13 AM <<<

:ph34r:
FYI…

IE7 0-Day Exploit Sites
- http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081210
Updated 12/14/2008 - 18:26 UTC/GMT:
( additions - Shadowserver recommended blocklist updates)
buxhere .com - 203.169.184.78 / [country: HK]

Updated 12/15/2008 - 04:17 UTC/GMT
517wyt .com - 66.90.67.98 / [country: US]

Highly recommended that you NOT visit these sites. "The majority if not all of them also house several other exploits for different vulnerabilities as well"…

:ph34r:
FYI… Shadowserver IEv7 0-day exploit sites / recommended blocklist sites…
Please do not visit -any- of these sites. The majority if not all of them also house several other exploits for different vulnerabilities as well…

- http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081211
11 December 2008 - "…We recommend blocking or looking for traffic to all of the sites we list*… but in particular as it related to this threat the following:
www .17gamo .com - 207.154.202.219 *seen from SQL injection attacks*
www .steoo .com - 97.74.35.98
evetlog .3322 .org - 218.9.170.106 …"

* http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081210
Updated 12/16/2008 - 13:09 UTC/GMT

vw. wd2a .cn - 218.83.161.134
927 .bigwww .com - 221.10.254.228
h3hs4 .cn - 218.6.12.75

Updated 12/14/2008 - 18:26 UTC/GMT:
buxhere .com - 203.169.184.78 / [country: HK]

Updated 12/15/2008 - 04:17 UTC/GMT
517wyt .com - 66.90.67.98 / [country: US]

(Keep checking the Shadowserver URLs frequently for new updates)

:ph34r: :ph34r: :ph34r:
FYI…

- http://isc.sans.org/diary.html?storyid=5497
Last Updated: 2008-12-16 20:23:07 UTC - "Microsoft has announced that they will be releasing an out of cycle security bulletin tomorrow for the IE zero day*…"
* http://www.microsoft.com/technet/security/…n/ms08-dec.mspx
December 16, 2008 - "…This bulletin advance notification will be replaced with the revised December bulletin summary on December 17, 2008. The revised bulletin summary will include the out-of-band security bulletin…
Bulletin Identifier: IE …
Aggregate Severity Rating: Critical …"

:ph34r:
FYI…

Microsoft Security Bulletin MS08-078 - Internet Explorer
Security Update for Internet Explorer (960714)
- http://www.microsoft.com/technet/security/…n/ms08-078.mspx
December 17, 2008
Severity Rating: Critical
Affected Software: Microsoft Windows, Internet Explorer…
Vulnerability Impact: Remote Code Execution…
(May require restart)

> http://support.microsoft.com/?kbid=960714
Last Review: December 18, 2008 - Revision: 2.0

:ph34r: