Category: Vista


 

 

Watch this folks.  I talk about this over and over.  a/v isn’t enough..it is only a start.  Please start with these basics.  Please contact ECC  on how to minimize your exposure.

 

 

The Internet Is Infected – 60 Minutes – CBS News.

Your Money or Your Business — Krebs on Security.

Just read this individuals blog.  There’s entry upon entry of businesses getting malware tuned to logging their keystrokes for the purpose of accessing their online bank accounts.  Just do a few things and you’ll be ok.

Microsoft has released the fix for the LNK issue. this coming Tuesday is going to be a monster patch day with a total of 37 issues fixed in 14 patches.

Normally I advocate caution in major patches.  This hole however is so important that i am going to immediately patch and then workaround any issues this is going to cause.  Again on mOnday htis patch gets released.  PATCH IMMEDIATLY!!!  Read the previous advisories I posted about this here.

Steve Gibson talks about this issue in a very understandable manner.  Look at my previous post at the bottom..aka update 3.

Well the vulnerabilities threat profile has expanded:
http://www.f-secure.com/weblog/archives/00001994.html
If the .lnk is inside a document windows will execute the code.  Again..i hope this fizzles..if it doesn’t I want folks to be aware.

Well the vulnerabilities threat profile has expanded:http://www.f-secure.com/weblog/archives/00001994.htmlIf the .lnk is inside a document windows will execute the code.  Again..i hope this fizzles..if it doesn’t I want folks to be aware.

http://www.emmanuelcomputerconsulting.com/archives/2421

The podcast software crashed so I was able to make a written update to the post with the help of Arstechnica.com.  Go checkout the updated post.

I am going to provide you with the summary from Ars Technica as it’s the clearest explanation of the problem I have seen:

The attack uses specially crafted shortcut (.lnk) files, which trick Windows into running code of an attacker’s choosing. Any Windows application that tries to display the shortcut’s icon—including Explorer—will cause exploitation, so even the mere act of browsing a directory with the malicious shortcuts is sufficient for a system to be exploited. Analysis suggests that the shortcuts are not improperly formed; rather they depend on a flaw in the way that Windows handles shortcuts to Control Panel icons.

The first reports of the problem came last month from Belorussian security company VirusBlokAda. The company found systems infected with the flaw through infected USB keys. The keys use the flaw to install a rootkit to hide the shortcuts, dubbed Stuxnet, including kernel-mode drivers, and a malicious payload. The rootkit is itself noteworthy: the drivers it installs are signed. The certificate used to sign them belongs to Realtek, suggesting that somehow the attackers have access to Realtek’s private key. The certificate used to sign the rootkit has now been revoked by Verisign.

The current in-the-wild attacks are using USB keys to distribute the shortcuts, but the attack could equally use network shares or local disks. The malware payload appears to be designed to specifically compromise the databases used by Siemens’ SIMATIC WinCC software. WinCC is SCADA software, used to control and monitor industrial systems, found in manufacturing plants, power generation facilities, oil and gas refineries, and so on. Siemens’ software uses hardcoded passwords, making attack particularly simple.

The best option for mitigating the flaw is to disable Windows’ ability to show shortcuts’ icons; details on how to do this are provided in Microsoft’s security bulletin. However, this mitigation comes at some cost; it removes all the icons from the Start menu, for example, which is sure to be detrimental to usability. Disabling Autorun provides slight protection, as it prevents Explorer windows from opening automatically when a USB key or CD is inserted.

This one has the potential to be very very bad.   What I am going to do is put some of the links below.  I am going to record a podcast tonight about this and have it posted in the next 24 hours.  While the threat right now is low the potential for this one to explode is very very high.  I do not get concerned about Windows exploits very often..this one has the very real potential to be on the scale of sasser, code red, or conficker.  ECC is gearing up for this to be a widespread event and I am hoping it fizzles(which is dependent on a timely patch from Microsoft.)  As of right now there is no anti-anything that will stop the .LNK vulnerability itself and any malware that appears WILL be able to leverage this before the a/v vendors can react as of right now.  I am sure the security companies will be able to catch up..however we really need a patch from Microsoft on this one.  The big problem for Microsoft is this is endemic to their ENTIRE codebase from Windows 95 on up.  They have to now re-engineer every version of Windows to protect against this flaw.  This is one time that if it takes Microsoft more than a week to come up with a fix there’s a very good reason. The following operating systems will NOT get a patch from Microsoft:

Windows 95

Windows 98

Windows ME

Windows NT

windows 2000(all versions)

Windows XP below SP3(this includes XP 64-bit which is now end of life..no support)

Windows VistaRTM (all versions).  Vista SP1 is still supported until July 12 2011.  You really should upgrade to SP2 of Vista.

I have some of the links below I have been following for this:

1

2

3

4

5

6

7

8

*UPDATE* Microsoft has posted their workaround.  This nukes ALL shortcuts on the system though.  If you want to guarentee your protection use this patch..but you won’t be able to easily launch anything.

*UPDATE 2*

Well the vulnerabilities threat profile has expanded:
If the .lnk is inside a document windows will execute the code.  Again..i hope this fizzles..if it doesn’t I want folks to be aware.
*UPDATE3*  List to this videocast from Steve Gibson..it’s well explained.

http://www.twit.tv/sn258

There are several attack vectors.  It can be triggered via a webpage.  it may even be able to be done from within any browser…not just IE.  I just just got done informing a client that this could have many more attack vectors due to this being a problem with the core of windows.

*UPDATE 4* Normally I advocate caution in major patches.  This hole however is so important that i am going to immediately patch and then workaround any issues this is going to cause.  Again on mOnday htis patch gets released.  PATCH IMMEDIATLY!!!  Read the previous advisories I posted about this here.

Windows has design issues…I have talked about it many many times.  However it IS possible to have a malware free system.  It’s really not that hard.  You do need to change your behavior on how you operate your windows systems.

1.  Have a security audit done if you’ve never had one done.

2.  Don’t use IE.  Unless you are technically savy just don’t.  It’s the number one attack vector(via Activex).

3.  Run Firefox or Google Chrome.

4.  Don’t goto porn, warez, gambling..etc etc type sites.  If it’s a red-light disctrict on land it’s the same in cyber-land.  If you go to these places in cyber-land none of the above or below matter..you’ll be infected either immediately or very quickly.  NO anti-anything will save you either.

5.  Don’t buy into the anti-whatever $$$ trap.  I haven’t run a/v on my systems in nearly a decade.  We’ve had ONE system infection and it was my wife’s fault(by her own admission).  If you are REQUIRED to run anti stuff get the  cheapest you can find.

6.  Never click a link in an e-mail until you check it.  This can be a tricky subject.  Hover your mouse(Don’t click any links) over the links and see if the address presented in the bottom bar matches the text of  the link.  If it doesn’t it’s a fake.  Contact ECC for full details.

7.  Remove admin rights from users.  Self-explanatory.

8.  Remove the ability for users to install ANYTHING.  This can easily be done via group policy. (This and #7 are the 2 things you can do on a network to stop at least 90% of all malware infections)

9.  Disable autorun.  This nukes most infections from usb keys(flash drives, thumb drives..etc etc etc.  Works great in conjunction with #8 and #7)

10.  Ensure all systems are up to date with all security updates.  Not just Windows and Office but every third party program on your systems.  (This includes Acrobat, Flash, Java).

Synchronizing Roaming Profiles Between a V1 & V2 Profile.

The news is..you can’t.  So if you want to move to server 2008 and keep your profiles you have to stick with either xp and below(not a good long term solution) or have all vista and above machines.  Users cannot roam between xp and vista/7 machines.  I guess MS REALLY wants you to upgrade to vista/7 when you change your server to 2k8.  ICK.  So the best migration is to manually grab the DATA(but not the config files) form the old profile..ahve the client log into the new machine and then dump the files into that…still an ick.  there are a FEW third party vendors that can migrate this via software but the costs could be substantial.