Go Back   vBulletin Setup > vBulletinSetup Information > vBulletin SEO Tips and SEO Questions > Search Engine News

Reply 
 
LinkBack Thread Tools Display Modes
Old 09-24-2006, 09:39 PM   #1
Community Manager
Supporters
vBulletin Owner
vBSetup Mods
 
Brandon Sheley's Avatar
 
Join Date: Jul 2006
Location: Topeka, KS
Posts: 14,115
Blog Entries: 35
Brandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to behold
Send a message via AIM to Brandon Sheley Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
Exclamation Third-Party Patch Out For IE's VML Bug

A group of security researchers on Friday posted an unsanctioned patch for the Internet Explorer VML bug, putting more pressure on Microsoft to push its own fix to users before its next scheduled update on Oct. 10.

Composed of at least 20 researchers in the U.S., Russia, Germany, and elsewhere, the Zeroday Emergency Response Team (ZERT) reverse-engineered a fix for the flaw disclosed earlier this week by Sunbelt Software. The fix can be downloaded from the ZERT Web site.

"While ZERT tests these patches, they are not official patches with vendor support and are provided as-is with no guarantee," the group said. "Use them at your own risk or wait for a vendor-supported patch."

Among those listed as ZERT members are Matthew Murphy, who blogs at the SecuriTeam site; Thor Larholm, who works for the Newport Beach, Calif.-based security company PivX Solutions Inc; and Ilfak Guilfanov, a Russian developer best known as the creator of the unsanctioned fix for the WMF vulnerability back in January.

"ZERT members work together as a team to release a non-vendor patch when a so-called '0day' (zero-day) exploit appears in the open which poses a serious risk to the public, to the infrastructure of the Internet or both," the group said.

Third-party patches for Microsoft gaffes are rare. The most recent and notable was Guilfanov's fix for a bug in Windows Metafile Format (WMF) image processing that he released several days before Microsoft rushed out its own update.

Pressure on Microsoft to fix the flaw may be mounting, said other security professionals, who have noticed increased attack activity. "VML attacks have ramped up significantly in the past 24 hours," said Ken Dunham, director of iDefense's rapid response team, in an e-mail to TechWeb. "At least one Domain Name Registration, E-mail, Web Hosting hosts provider has suffered a large-scale attack leading to index file modifications on over 500 domains to redirect users to a hostile VML exploiting site," Dunham continued.

Eric Sites, vice president of research and development at Sunbelt Software, which first reported the vulnerability and exploit earlier this week, also said that attacks were "definitely escalating." In a conversation with a tier 1 support representative at Cox Cable on Friday, Sites said, he was told that the cable operator had several thousand support calls and e-mails backed up, with users reporting a wide variety of complaints, including IE crashes. "That may be a targeted attack," said Sites.

Both Dunham and Sites warned of even larger attacks over the weekend.

"[Users should] implement a workaround ASAP due to imminent global attacks," said Dunham.


"There are a lot more sites using [a VML exploit]," added Sites.

Part of their concern is that the exploit may quickly move to e-mail, with spam-style attacks compromising PCs as soon as the recipient views an infected message in an cPanel preview pane. Symantec, for example, confirmed Friday that a working exploit against Microsoft Outlook has been written and posted by Immunity Inc. for its CANVAS exploit framework.

An e-mailed attack is dangerous because it requires no out-of-the-ordinary user action, said Sites. "If you see a message in the Preview Pane or double default parking homes for sale at click it, a well-crafted exploit will crash Outlook. You won't see any error message." As soon as that happens, the attacker can begin loading a user's PC with adware, spyware, and other malicious code, he added.

Sunbelt's testing has confirmed that Outlook 2003 is vulnerable -- in its most-patched SP2 version at least -- but that earlier editions of the e-mailer, including Outlook 2000 and Outlook 2002, are not at risk. Sunbelt has yet to test Outlook 2003 SP1.

To protect against e-mailed attackers, Outlook users should disable the Preview Pane (in Outlook 2003, select View|Reading Pane|Off) and render all mail in plain text (Tools|Options|Preferences|E-mail Options, then check the "Read all standard mail in plain text" box.).

But installing the ZERT patch may be a risky move, concluded Sites. "The problem is that you'll never know if it works in all situations," he said. "There's a reason why it takes Microsoft time to test a patch."

However, Sites expects that Microsoft will go out-of-cycle with a fix if the situation worsens. "With the e-mail vector possible, I think it'll be maybe another week, maybe less, before Microsoft releases [a patch]."
__________________
Brandon Sheley / vBulletinSetup Staff
Check the Newsletter & Marketplace for the latest deals.
Looking for a place to Support vBulletinSetup?
Submit your Forum and other Quality Websites.


Brandon Sheley is offline   Reply With Quote

Advertisement [Remove Advertisement]

Reply 
vBulletin Setup > vBulletinSetup Information > vBulletin SEO Tips and SEO Questions > Search Engine News

Tags
bug, patch, thirdparty, vml

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Established SMS Text Messaging & Party Website For Sale Auctions Webmaster Auctions 0 06-30-2009 07:42 AM
Harley Davidson H.O.G. Officer Patch Webmaster patch News Webmaster Auctions 0 04-29-2009 05:39 PM
NEW At Home Entertaining: The Art of Hosting a Party... News Webmaster Auctions 0 04-12-2009 09:52 AM
My Golf Party Forum Brandon Sheley vBulletin Setup Clients 0 03-09-2008 09:32 PM
So Where Is The big New Years Eve Party? Code Monkey General Discussion 2 12-29-2006 09:53 AM


All times are GMT -8. The time now is 03:34 PM.