The Wayback Machine - https://web.archive.org/web/20080405173652/http://blogs.zdnet.com:80/security/
BNET Business Network:
BNET
TechRepublic
ZDNet

April 4th, 2008

Taking ownership of content

Posted by Nathan McFeters @ 9:51 am

Categories: Hackers, Browsers, Vulnerability research, Exploit code, Data theft, Google, Sun Microsystems, Java, Adobe, Flash

Tags: Domain, Applet, JVM, Billy Rios, Class File, CODE, Java, Programming Languages, Software Development, Software/Web Development

Billy RiosBilly Rios covered a very interesting flaw in Google’s code.google.com site on his blog today.  The issue involves taking ownership of content of a third party by an application and relates to research that Rios and I originally presented at DEFCON 15 last year.

Before I go any further, I’d like to say that the Google Security Team (GST) is great to work with. Rios and I have had numerous vulnerabilities that we’ve reported to various companies and there simply is no one that handles things as quickly or communicates as well with the researchers. As Rios mentioned on his blog entry, this is a non-trivial exploit to fix, and they did it fast. Now, before someone accuses me of playing favorites or being biased, I’ll answer that with a “Yep, I am biased in this case.” I’ll admit it. I’d rather work with someone who listens to what I say, responds professionally, and takes into consideration my own counter arguments. OK, that said, onto the details.

Really, I’m not sure we should call it taking ownership of content as much as we should call it taking “pwnership” of content, as this is a serious pinch point for applications.  Rios gives the expert explanation of this issue, so I will paraphrase his blog entry for our discussion. Rios says:

On to the issue:
I discovered that users could upload arbitrary files to the code.google.com domain by attaching a file to the “issues” portion of a project.  The uploaded file is then served from the code.google.com domain.  Normally, these types of attacks would make use of the Flash cross domain policy file and the System.security.loadPolicyFile() API, however due to the unique path of each project, the cross domain capabilities of Flash are very limited in this instance as policy files loaded via loadPolicyFile() are “limited to locations at or below its own level in the server’s hierarchy”. 

Ok, so the key to this is that we aren’t going to use Flash.  As Rios states below, we’re going to use Java so that we can get around of some of the limitations that Flash has for this type of attack:

Java has a different security policy and uploading a Java class file to the code.google.com domain gives me access to the entire domain, as opposed to only certain folders and sub folders. 

Awesome, this gives us exactly what we need then, and a very useful attack vector; however, there’s some complications, as Rios mentions:

Sounds pretty straight forward huh?  Well, I ran into some issues as the JVM encodes certain characters in its requests for class files made via the CODE attribute within APPLET tags.  After poking around a bit, I realized that requests made via the ARCHIVE would be sent as is, without the encoding of special characters.  With this newfound knowledge in hand, I created a JAR file with my class file within it and uploaded it to code.google.com.

Issues Upload

Now, the CODE attribute is a required attribute within the APPLET tag, so I specified name of the class file I placed within the JAR file.  When the APPLET tag is rendered, the JVM first downloads the JAR file specified in the ARCHIVE attribute, the JVM then makes the request for the class file specified in the CODE attribute.  In this instance, the request for the class file specified in the CODE attribute will fail as the class file is not on the code.google.com server (even if it was, we wouldn’t be able to reach it as requests made via the CODE attribute are encoded).  The failure to locate the class file causes the JVM to begin searching alternate locations for the requested class file and the JVM will eventually load a class file with the same name located inside of the JAR file…

Applet Code  

Once the class file is loaded, the JVM will fire the init() method and Java’s Same Origin policy allows me to use the applet to communicate with the domain that served the applet class file (as opposed to the domain that hosts the HTML calling the APPLET tag).  Here’s a screenshot of the PoC page I was hosting on XS-Sniper.com. 

Proof of Concept

Wow, pretty visual PoC, eh?  I hate the idea of using my Google password!

I don’t think there is a tool on the market today that even attempts to detect something like this and I’ve met many “security professionals” that have no idea that vulnerabilities like this even exist.  This isn’t the first time I’ve come across a cross domain hole based on content ownership.  I’m expecting we’ll see a lot more of these types of vulnerabilities in the future as cross domain capabilities becomes more prevalent in client side technologies and as content providers become more and more comfortable in taking ownership of others content.

Like Rios mentions, you can buy all the tools and web application firewalls you’d like, it doesn’t protect you from this issue, or from making your own mistake in creating this issue on your own web application.  There’s no substitute for design review and application security testing.

-Nate

April 3rd, 2008

Microsoft readies Vista, Windows Server 2008 critical patches

Posted by Larry Dignan @ 11:13 am

Categories: Patch Watch, Microsoft, Windows Vista, Vulnerability research, Exploit code

Tags: Microsoft Windows Server, Vulnerability, Patch Management, Microsoft Windows Vista, Microsoft Corp., Bulletin, Microsoft Windows, Microsoft Windows Server 2008, Microsoft Windows Vista (Longhorn), Servers

Microsoft on Thursday issued five critical security bulletins and three important ones for all flavors of Windows, Internet Explorer and Office. Vista and Windows Server 2008 are affected by four of the five critical bulletins.

In its patch day advance notification for its Tuesday update, Microsoft issued five critical bulletins to address remote code execution vulnerabilities. Microsoft said it will patch critical flaws in Vista, Windows Server 2008, Windows Server 2003 (SPs 1 and 2), IE 6 and 7 and Office XP SP3, 2003 and 2007 Microsoft Office System among others.

Details of these vulnerabilities will be disclosed on Tuesday.

Among the three important vulnerabilities, the affected software includes Windows Server 2003 and 2008, Vista and Vista SP1 and Visio 2002, 2003 and 2007.

Microsoft has issued 25 security bulletins so far this year.

April 3rd, 2008

Apple patches 11 QuickTime flaws

Posted by Larry Dignan @ 10:49 am

Categories: Patch Watch, Apple, Vulnerability research, Exploit code

Tags: Java Applet, Apple QuickTime, Java, Movie, Apple Inc., Applet, Flaw, CVE-2008-1014, Movie File, CVE-2008-1015

Apple pushed out the latest version of QuickTime and patched 11 vulnerabilities in its third security update of 2008.

Late Wednesday, Apple pushed the update, which covers QuickTime on all platforms. The following flaws affect QuickTime on Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Mac OS X v10.5 or later, Windows Vista, XP SP2 unless noted otherwise. Among the key patches:

CVE-2008-1013 fixes a flaw where Java applets allow for elevated privileges. Apple says:

An implementation issue in QuickTime for Java allows untrusted Java applets to deserialize objects provided by QTJava. Visiting a web page containing a maliciously crafted Java applet could allow the disclosure of sensitive information, or arbitrary
code execution with the privileges of the current user. This update addresses the issue by disabling the ability of untrusted Java applets to deserialize QTJava objects.

CVE-2008-1014 addresses an information disclosure issue that occurs when a user downloads a movie. Apple says:

Specially crafted QuickTime movies can automatically open external URLs, which may lead to information disclosure. This update addresses the issue through improved handling of external URLs embedded in movie files.

CVE-2008-1015 addresses another movie file issue. A maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution, says Apple, adding “an issue in QuickTime’s handling of data reference atoms may result in a buffer overflow.”

CVE-2008-1016, CVE-2008-1017 and CVE-2008-1018 all address flaws that lead to code execution and application termination issues for folks that download malicious movies.

CVE-2008-1019 addresses “a maliciously crafted PICT image file (that) may lead to an unexpected application termination or arbitrary code execution.” CVE-2008-1020 and CVE-2008-1023 addresse a PICT image file flaw only Vista and XP SP2.

CVE-2008-1021 fixes another movie file flaw that can terminate an application or lead to a code execution vulnerability. Platforms affected are Vista and XP SP2.

CVE-2008-1022 addresses an QuickTime VR movie flaw. “Viewing a maliciously crafted QuickTime VR movie file may lead to an unexpected application termination or arbitrary code execution,” says Apple.

April 3rd, 2008

Adobe claims to have known of Flash issue prior to CanSecWest ‘08, patch is on the way

Posted by Nathan McFeters @ 8:01 am

Categories: Patch Watch, Zero-day attacks, Vulnerability research, Responsible disclosure, Exploit code, Adobe, Flash

Tags: Adobe Systems Inc., Patches, Security, Team Management, Management, Nathan McFeters

In a comment in a talkback on the original issue discovered in Adobe Flash that led to the compromise of the Vista machine at the Pwn2Own contest, an Adobe representitive, Erick Lee, Manager of Adobe Secure Software Engineering Team (ASSET), claimed that Adobe knew of the flaw and has a patch on the way. 

This announcement acknowledges that Adobe knew of the risk, accepted it as their own, and was working on fixing it.  Kudos to Adobe for having been on the ball getting this going and into a patch.  An excerpt from their blog addresses this:

On Friday March 28, 2008 during the CanSecWest 2008 security conference Shane Macaulay of Security Objectives uncovered a potential security issue with Flash Player. Adobe Product Incident Response Team (PSIRT) received information regarding the exploit from TippingPoint, who sponsored the contest, on Friday evening. After some internal investigation, we found that via our ongoing response and security testing process we were aware of the issue and had fixed it for our security update coming in the next Flash Player update later this month.

What should I do as a customer?

We have fixed the issue and it will be in our next update coming later this month. Adobe is not aware of any active exploits in wild. The security researchers have reported the information to us responsibly giving the Flash Player team time to investigate and deliver a patch to you. We will provide more information as it becomes available.

*This posting is provided “AS IS” with no warranties, and confers no rights.*

April 3rd, 2008

“How do I?” videos for security

Posted by Nathan McFeters @ 7:06 am

Categories: Microsoft

Tags: Security, Video, Corporate Communications, Marketing, Nathan McFeters

While checking out Billy Rios’s XS-Sniper blog today, I noted that he had included an interesting link to some videos produced by Microsoft.  I haven’t had a chance to check them all out yet, but they are quite interesting.  These “How do I?” videos provide video tutorials to address certain issues, such as, “How do I fix SQL Injection?” or “How do I prevent Cross-Site Request Forgery?”.

These videos are .NET focused, but I’m sure some of the techniques will apply nicely across the board, even if the code or technology used is a bit different.  Some of the videos even cover fixing issues on other platforms, which I think is pretty nice.  Hopefully these videos will proove helpful to those of our readers who are struggling with some of these security topics.

I’d be interested in hearing thoughts about the impact of these videos.

-Nate

April 2nd, 2008

Interview with the Vista Pwn2Own contest winners

Posted by Nathan McFeters @ 6:00 am

Categories: Hackers, Zero-day attacks, Microsoft, Windows Vista, Vulnerability research, Responsible disclosure, Exploit code, Sun Microsystems, Java

Tags: Adobe Systems Inc., Vulnerability, JavaScript, Microsoft Windows Vista, Exploit, Data Execution Prevention, Flaw, Nate, Programming Languages, Java

Update 04/03/2008: I’ve updated the article as apparently the link to k2’s blog was broken.  Also, it’s important to note that Derek Callaway was a part of this research and exploitation as well, and I neglected to mention that.

So obviously our coverage of the Pwn2Own contest has received a lot of attention (see: MacBook Air falls in two minutes at PWN 2 OWN; Vista falls in Pwn2Own contests final day to a flaw in Adobe Flash; More details on the Pwn2Own Flash flaw that won the Vista machine; and Pwn2Own: What OS really won?) in the talkbacks and there have been some very heated debates over a few sticking points, especially in the discussion of the Flash flaw which compromised Vista. It’s been outstanding and I thank everyone who was involved in these discussions, especially n0neXn0ne and OButterball, who I personally had very long and detailed debates with.

Here’s a list of what the key issues debated on were:

  1. Who won (or who lost, depending on who’s answering the question) the Pwn2Own contest? To be clear, when I say who, I mean, which OS.
  2. Who all was vulnerable to the Adobe Flash flaw?
  3. Is the Adobe Flash flaw Adobe’s fault, the fault of the operating system? (Sun’s fault?)

Well, I thought it would make sense to go straight to the source of the Adobe Flash exploit to get some first-hand accounts of what went down, so I interviewed Shane Macaulay (aka k2, pictured on the right in the image taken from the ZDI website) and Alexander Sotirov (pictured on the left in the image taken from the ZDI website). It was a great interview, which I present below:

Nate: The flaw you discovered was in Adobe Flash, was this truly a cross-platform attack?

Shane: Yeah, there’s a stack issue, where a type is accepting 3 parameters when it is defined to accept 2, possibly some polymorphism/name mangling bug, but either way, this object get’s called through the 3rd invalid/uninitialized memory that winds up jumping wherever we had pre-filled memory to.

Nate: So then, do you have exploit code for all three of the operating systems, or are you certain that you could’ve written exploit code given enough time?

Shane: Could have been done with enough time, I haven’t used gdb in years, that’s the main hurdle right now. My professional career has been on the Microsoft platform so I’ve not had the time to work with *nix much.

Nate: Why choose Vista over *Nix or the Mac?

Shane: Oh I guess I just answered that one. Not to mention once the flaw was used once, we couldn’t use it again to pwn the other machines.

Nate: So, the InfoWorld article mentions that you brought Alexander into the mix for some additional Ninjitsu and that the use of Java was involved… can you confirm my assumption that you used a Java applet to bypass the DEP restrictions (since JVM doesn’t play nice with DEP) and that this is a buffer overflow type issue within Flash?

Shane: I’ll defer to the esteemed Mr. Sotirov

Alex: The target machine had a non-executable heap in the Internet Explorer process, which prevented Shane from using JavaScript heap spraying to execute shellcode on the heap. I had done some research on bypassing DEP and I had an exploitation technique that we could use in this exploit. We utilized a Java applet to allocate executable memory and fill it with shellcode. I’d like to point out that this is not a vulnerability in Java, but simply a way to use Java applets to make the exploitation of other vulnerabilities easier. I have a few other techniques for bypassing DEP, so the Flash vulnerability could have been exploited without Java as well.

Nate: Considering Sotirov is well known for his “Javascript Heap Fung Shui” did that come into play here? Did you use Java or JavaScript to prepare the heap for this exploit to work?

Shane: I guess we shouldn’t answer a question phrased like that. We did not need the Fung Shui, but both Java and JavaScript were used. There is some chance that ActionScript could’ve been used, but that would have tweaked the target.

Alex: The Heap Feng Shui technique was not needed for exploiting this vulnerability, but Charlie Miller used an OSX port of my Heap Feng Shui library to pwn the MacBook Air on day two. I think it’s pretty cool to have my code involved in winning both laptops this year.

Nate: Yeah, that is bad ass. I’ve actually used your Heap Feng Shui attacks in my own research, but I was unaware that there was a port to Mac… that’s very interesting and likely makes my job a bit easier going forward! Any more details you can give on where the exploit occurred within flash?

Shane: I think we have to plead the fifth, until the bulletin is issued, save details in question 1.

Nate: What are you going to do with the money and laptop?

Shane: B0000m Ebay!! If the laptop was even 1/4 as good as the MacBook I got last year I would of kept it, but as it turns out, I had to add in a +1GB of ram for the offer on eBay to make sure it’s a solid box for whoever gets itAlex: I’m doing this for the chicks, not the money.

Nate: HAHAHAAHA! So, Shane, after two years of being on the successful winning team, how long do you think you can keep the streak going? Will you be attempting a three-peat?

Shane: I’ve been considering the trifecta, I’ve got an IE 0day in the hopper now (see my previous best bug ever in IE, http://systemofsystems.wordpress.com/2008/02/12/dime%e2%80%99s/), I’ll blow the dust off some exploit for use in the contest for sure.

Nate: What’s up next for you guys? Any cool research you’re currently looking into?

Shane: Myself, largely a product, a binary application attack system. Some features include:

  • Very high test speed (usually in the tens of thousands/sec on a single
    core)
  • Identified issues are categorized based on there type, read/write/exec/…
  • Code/data trace model and reverse execution
    • Helps pinpoint original flaw location
  • Optimized set generation code for inputs
  • Generates test cases for fixes
    • Not just error messages

Basically, it’s a solid dynamic analysis engine with advanced data analysis for binary steering, data flow comprehension and attack capabilities. No sources required.

Alex: I have some research on bypassing DEP and ASLR that I plan to present at a future conference, as well as some social networking exploitation work. Stay tuned!

Nate: Very interesting indeed!

So, for those who have been reading up on the previous articles, there’s some info for you straight from the researchers themselves. Thanks a lot Shane and Alex for taking the time! To the readers, if you have follow-up questions that you want asked, you can submit them to me via talkback and I’ll do the best I can to get some answers from these guys, although keep in mind they are under NDA.

-Nate

April 1st, 2008

Rejoice!!! Scanless PCI is here!

Posted by Nathan McFeters @ 10:30 am

Categories: Uncategorized

Tags: PCI, Web Site Development, Storage, Hardware, Internet, Nathan McFeters

Why are we still talking about the value of PCI Compliance?  Now we can all get it for free due to a great new product!  It’s called Scanless PCI.  The premise is pretty simple, go to the website, grab the code, throw it on your website and poof. You’re PCI certified. No fuss, no muss.

Go get it today!

-Nate

April 1st, 2008

Changes to British law will affect computer security industry

Posted by Nathan McFeters @ 7:22 am

Categories: Hackers, Vulnerability research, Responsible disclosure, Governments, United States of America, United Kingdom

Tags: Computer Security, Commission, Industry, Hacker, Tool, Computer, Ristic, Guidance, Productivity, Security

Ivan RisticIvan Ristic (pictured to the right) posted a story today on his blog that highlights some changes that are to go into effect in England sometime this year.  The changes to the Computer Misuse Act (CMA) would appear to put security researchers and consultants in the UK at risk of being considered criminals. Ristic mentions the key proposed additions below:

The key proposed addition in reads as follows (a marked-up copy of the changes is available, courtesy of Clive Feather):

3A Making, supplying or obtaining articles for use in offence under section 1 or 3

  1. A person is guilty of an offence if he makes, adapts, supplies or offers to supply any article intending it to be used to commit, or to assist in the commission of, an offence under section 1 or 3.
  2. A person is guilty of an offence if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence under section 1 or 3.
  3. A person is guilty of an offence if he obtains any article with a view to its being supplied for use to commit, or to assist in the commission of, an offence under section 1 or 3.
  4. In this section “article” includes any program or data held in electronic form.
  5. A person guilty of an offence under this section shall be liable—
    • on summary conviction in England and Wales, to imprisonment for a term not exceeding 12 months or to a fine not exceeding the statutory maximum or to both;
    • on summary conviction in Scotland, to imprisonment for a term not exceeding six months or to a fine not exceeding the statutory maximum or to both;
    • on conviction on indictment, to imprisonment for a term not exceeding two years or to a fine or to both.

The main issue is the ambiguity of the word likely in “[…] likely to be used to commit, or to assist in the commission of, and offence […]”, which effectively criminalises a large number of security professionals who are just doing their jobs.

I think we all know that the tools a security researcher/consultant uses are the same (for the most part, likely minus some Ninja scripts/tools that some hackers keep private) as those hackers use.  I’m a security researcher and a security consultant as a full-time job; however, I also consider myself a hacker.  The only time I’m doing anything malicious is when I’m playing pranks on friends (mostly Mike Wood), but to me, what defines someone as a hacker is their mindset.  I think most people understand that these days.  Governments are just a few years behind the curve apparently, and it is dangerous to all of us in this profession.

It seems like every law that comes out related to computer security is either so vague it loses its bite (see PCI), or so vague it allows people who aren’t even guilty of anything evil to be implicated and treated as criminals (see my recent post on the new laws to crack down on child pornography).  It’s a scary world we live in.  I’m not big into politics, but as a US citizen, this is a disturbing trend to me.  I wonder if the US is beginning to consider similar non-sensical (I don’t even think that’s a real word that’s how fired up I am right now) laws.

As Ristic mentions:

A much bigger problem is that the new law leaves too much to interpretation. The risk is just too high: do you want to be in a position to defend your actions in front of a jury that will almost certainly fail to understand the subject matter? Even if you are successful in your defence, such an event will require significant financial resources, disrupt your life, cause you and your family endless pain, and most certainly kill your career.

I mean, how do you even go about hiring a lawyer if you are implicated of something like this?  I’d actually feel more comfortable representing myself with my very limited knowledge of law than I would hiring an attorney with a very limited knowledge of computers.

Further, Ristic mentions the possible outcomes of this law coming into effect:

Possession it not likely to be criminalised (from the Guidance: “[…] does not criminalise possession per se unless an intent to use it to commit one of the other offences in section 1 or 3 CMA can be shown.“) so it will probably still be safe to research computer security in private, but exchanging information with others might become dangerous. With the threat of persecution hanging over their heads, most people in the UK are likely to stop publicly discussing what they know.

Full disclosure—no matter what you think of it—will be criminalised, but it won’t go away. Those who believe will continue to release vulnerability information, but they will likely take precautions to keep their identities secret.

Tool authors will have a choice to make. If they don’t change their distribution practices they will risk becoming a target of investigation and, possibly, prosecution. The Guidance seems to imply the safe way to distribute the tools is via a vetted list of computer security professionals. This is not feasible for most tool writers as they cannot afford the overhead of such a process. On top of that, even if such practices are followed, there is still no guarantee that you won’t be persecuted. Each case will be reviewed on its own merits. Thus the alternatives—ending further development or moving the tools underground—seem far more likely.

So great idea, let’s just go ahead and nab all those evil security researchers and consultants who keep trying to make our systems more secure, since we can catch them, as they are public enough to be seen.  Then, we’ll completely miss out on all those underground hackers who are actually doing the evil deeds, cause we have neither the time, people, nor skill to catch them.

Way to think it through guys.  Well played.

-Nate

March 31st, 2008

Pwn2Own: What OS really won?

Posted by Larry Dignan @ 1:05 pm

Categories: Apple, Microsoft, Windows Vista, Vulnerability research, Exploit code, Open source

Tags: Ubuntu, Operating System, Apple MacBook, Microsoft Windows Vista, Apple Inc., Hacker, Pwn2Own, Notebooks, Microsoft Windows Vista (Longhorn), Hardware

Apple had a rough security week. Vista was hacked. And Linux is unhackable. Those takeaways appear to be the consensus view following the Pwn2Own contest but it’s not that simple.

Under the contest rules, organizers offered the Sony Vaio (Ubuntu 7.10), Fujitsu U810 (Vista Ultimate), and the MacBook (OS X 10.5.2) as prizes. Sure, the MacBook fell first at the Pwn2Own contest at CanSecWest last week. And yes, the MacBook was fully patched and still fell. But the odds were strong that the MacBook would have been the first to fall no matter what Apple did.

Why?

Glory. Taking down a MacBook gets the headlines. It’s sexy. It’s a blogger’s dream. The more prominent Apple becomes the more hackers want to attack it. Simply put, security by obscurity isn’t an option for Apple anymore. Why wouldn’t hackers target the MacBook first? 

Based on that aforementioned theory MacBook’s fate was sealed.

I reckon that Vista actually had a good week at the Pwn2Own contest. As Nate dutifully noted Vista was hacked, but the rules had to be tweaked and hackers used an Adobe flaw to take the Vista laptop. I’d count that as a moral victory for Microsoft. What’s a hacking contest without a Vista hack?

And that brings me to the Ubuntu laptop. Linux made it out of Pwn2Own unscathed. Does that mean that Ubuntu is unhackable? Not quite. It just means that hackers didn’t see the glory in taking down Ubuntu, which is a small sliver of the desktop OS market. Rest assured, if Pwn2Own ran another day Ubuntu would have stumbled too.

When you see Ubuntu hacked repeatedly you know the Linux OS has hit the big leagues. Vulnerabilities follow success.

March 31st, 2008

More details on the Pwn2Own Flash flaw that won the Vista machine

Posted by Nathan McFeters @ 11:39 am

Categories: Hackers, Zero-day attacks, Microsoft, Windows Vista, Vulnerability research, Responsible disclosure, Exploit code, Sun Microsystems, Java

Tags: Java, Microsoft Windows Vista, Data Execution Prevention, Flaw, Microsoft Windows Vista (Longhorn), Security, Operating Systems, Microsoft Windows, Software, Nathan McFeters

Alexander Sotirov (SolarEclipse) and Shane Macaulay (k2)So, I’ve been pretty surprised by the response to the discussion of the Flash flaw that allowed the Vista machine to be compromised in the Pwn2Own contest.  I’m working on getting an interview with Alexander Sotirov and Shane Macaulay (see image, courtesy of ZDI’s official site) to discuss the issue, but in the meantime, I think we can make some reasonable assumptions from the details that have been released in an InfoWorld article:

Macaulay, who was a co-winner of last year’s hacking contest, needed a few hacking tricks courtesy of VMware researcher Alexander Sotirov to make his bug work. That’s because Macaulay hadn’t been expecting to attack the Service Pack 1 version of Vista, which comes with additional security measures…

For those who aren’t familiar with Sotirov, he’s of the Javascript Fung Shui fame, which is basically a new method of heap spraying that allows the exploit code to have a predictable target address where it will be located in the heap.  So they team up and get to work:

Under contest rules, Macaulay and Miller aren’t allowed to divulge specific details about their bugs until they are patched, but Macaulay said the flaw that he exploited was a cross-platform bug that took advantage of Java to circumvent Vista’s security.

Hmmm… does this sound familiar to anyone?  See my posts (part 1 here and part 2 here) on the flaws that John Heasman spoke of in Java which require it to turn off features like DEP in operating systems that provide these protections.  So my guess, and I feel it is an educated one (of course time will tell), is that Sotirov helped out by providing some additional hacker ninjitsu by helping Macaulay load this Flash attack through a Java Applet, thus turning off any DEP protections the operating system provides.  Heck, I wouldn’t even be surprised if he used the applet to do some fancy heap spraying to load the shellcode from the heap.  The article continues:

“The flaw is in something else, but the inherent nature of Java allowed us to get around the protections that Microsoft had in place,” he (Macaulay) said in an interview shortly after he claimed his prize Friday. “This could affect Linux or Mac OS X.”

Macaulay said he chose to work on Vista because he had done contract work for Microsoft in the past and was more familiar with its products.

Aha, so there is your story right there, this flaw could’ve worked on any of the systems; however, the contest rules state that the same exploit can only be used to compromise one machine (see rule #2 from the cansecwest.com web page which states “You can’t use the same vulnerability to claim more than one box, if it is a cross-platform issue.”), and Macaulay used Vista because it was what he was more familiar with.

So I guess we can end the OS wars about who’s is better.  Perhaps I could just put up a poll so we could vote on it and get that all over and done with.  So now, we should be pointing the finger at Adobe for allowing this flaw… or wait a minute, should we be pointing it at Sun since it doesn’t play nice with DEP?

-Nate

Nathan McFeters

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. The views and opinions expressed in this article are his own and do not represent the views and opinions of Ernst & Young Advanced Security Center or Ernst & Young, LLP. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios. See his full profile and disclosure of his industry affiliations.

advertisement

Recent Entries

Most Popular Posts

advertisement

Archives

ZDNet Blogs

Popular white papers

I/O Virtualization

From our sponsors

HP StorageWork 4400 Enterprise Virtual Array

advertisement
Click Here