<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; windows-exploit</title>
	<atom:link href="http://www.darknet.org.uk/tag/windows-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>winAUTOPWN v2.8 Released For Download &#8211; Windows Auto-Hacking Toolkit</title>
		<link>http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/</link>
		<comments>http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/#comments</comments>
		<pubDate>Tue, 18 Oct 2011 17:27:26 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[auto hacking]]></category>
		<category><![CDATA[auto hacking tool]]></category>
		<category><![CDATA[automated exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit tool]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[win hacking tool]]></category>
		<category><![CDATA[winautopwn]]></category>
		<category><![CDATA[windows-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3205</guid>
		<description><![CDATA[I wanted to post this a while back, but the site (and thus the download) was down again &#8211; it seems to be a common occurrence. Someone get this guy some proper hosting! winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP [...]]]></description>
			<content:encoded><![CDATA[<p>I wanted to post this a while back, but the site (and thus the download) was down again &#8211; it seems to be a common occurrence. Someone get this guy some proper hosting!</p>
<p>winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 to 65535. Exploits capable of giving Remote Shells, which are released publicly over the Internet by active contributors and exploit writers are constantly added to winAUTOPWN/bsdAUTOPWN. A lot of these exploits are written in scripting languages like python, perl and php. Presence of these language interpreters is essential for successful exploitations using winAUTOPWN/bsdAUTOPWN.</p>
<p>Exploits written in languages like C, Delphi, ASM which can be compiled are pre-compiled and added along-with others. On successful exploitation winAUTOPWN/bsdAUTOPWN gives a remote shell and waits for the attacker to use the shell before trying other exploits. This way the attacker can count and check the number of exploits which actually worked on a Target System.</p>
<p>This version covers almost all remote exploits up-till September 2011 and a few older ones as well. Also added in this release are a few ruby exploits which require &#8216;socket&#8217; alone for interpretation. Gee-Hence, winAUTOPWN now requires ruby installed as well, just like perl, python and php.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>This version incorporates a new command-line parameters: -targetOS to allow selection of the target Operating System. This is essential for a few exploits to work perfectly. The List of OS and the corresponding OS codes are available and asked when winAUTOPWN OR bsdAUTOPWN is executed.</p>
<p>Untill the last release there was only a bind_shell TCP shellcode available in the exploits. This release brings yet another feature which gives the freedom to choose from a variety of shellcodes. You can now select reverse_tcp for Windows cmd and other shellcodes for Solaris, Linux, FreeBSD, etc. This is all done by mod_shellcode which has been created and added to WINDOWS AUTOPWN and BSD AUTOPWN as well. mod_shellcode gets automatically invoked by WINDOWS AUTOPWN for every scripted exploit code whose shellcode can be manually changed. Note that there are a few exploits in a compiled binary form which lack reverse shell and other shellcode features.</p>
<p>mod_shellcode is available as a separate binary in the exploits/ directory for Windows, FreeBSD x86, FreeBSD x64 and DragonFly BSD platforms (just like the main BSD AUTOPWN and other exploit binaries) and hence can also be manually used by exploit writers and exploiters to quickly change shellcodes in their exploit files.</p>
<p>You can download winAUTOPWn v2.8 here:</p>
<p><a href="http://27.106.39.222/w/winAUTOPWN_2.8.7z">winAUTOPWN_2.8.7z</a></p>
<p>And well because the site is always down, I&#8217;ve uploaded a mirror copy here:</p>
<p><a href="http://www.filesonic.com/file/2644314211/winAUTOPWN_2.8.7z">winAUTOPWN_2.8.7z (FileSonic)</a></p>
<p>Or read more <a href="http://winautopwn.co.nr">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3205+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;t=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fwinautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>winAUTOPWN v2.7 Released &#8211; Windows Autohacking Tool</title>
		<link>http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/</link>
		<comments>http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/#comments</comments>
		<pubDate>Tue, 06 Sep 2011 10:45:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[auto hacking]]></category>
		<category><![CDATA[auto hacking tool]]></category>
		<category><![CDATA[automated exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit tool]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[win hacking tool]]></category>
		<category><![CDATA[winautopwn]]></category>
		<category><![CDATA[windows-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3085</guid>
		<description><![CDATA[I&#8217;ve always been skeptical about this tool, especially seen as though the first version was released on April Fools day in 2009, anyway it&#8217;s 2 years later now and it still seems to be around so I think it&#8217;s worth publishing an update. If any of you have actually tested this tool out, do drop [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve always been skeptical about this tool, especially seen as though the first version was released on <a href="http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/">April Fools day in 2009</a>, anyway it&#8217;s 2 years later now and it still seems to be around so I think it&#8217;s worth publishing an update.</p>
<p>If any of you have actually tested this tool out, do drop a comment below.</p>
<p>winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 to 65535. Exploits capable of giving Remote Shells, which are released publicly over the Internet by active contributors and exploit writers are constantly added to winAUTOPWN/bsdAUTOPWN. A lot of these exploits are written in scripting languages like python, perl and php. Presence of these language interpreters is essential for successful exploitations using winAUTOPWN/bsdAUTOPWN.</p>
<p>Exploits written in languages like C, Delphi, ASM which can be compiled are pre-compiled and added along-with others. On successful exploitation winAUTOPWN/bsdAUTOPWN gives a remote shell and waits for the attacker to use the shell before trying other exploits. This way the attacker can count and check the number of exploits which actually worked on a Target System.</p>
<p><strong>New in v2.7</strong></p>
<p>This version covers almost all remote exploits up-till mid-July 2011 and a few older ones as well.  This version incorporates a few new commandline parameters: -perlrevshURL (for a PERL Reverse Shell URL), &#8211; mailFROM (smtpsender) and -mailTO (smtpreceiver).  These are the commandline arguments required for a few exploits which require remote connect-back using a perl shell and email server exploits requiring authentication respectively.  This version also tackles various internal bugs and fixes them.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p> A complete list of all Exploits in winAUTOPWN is available in CHANGELOG.TXT<br />
 A complete list of User Interface changes is available in UI_CHANGES.txt</p>
<p>Also, in this version :</p>
<ul>
<li> BSDAUTOPWN has been upgraded to version 1.5.</li>
<li> In this release you will also find pre-compiled binaries for :</li>
<li> FreeBSD x86</li>
<li> FreeBSD x64</li>
<li> DragonFly BSD x86</li>
</ul>
<p>You can download winAUTOPWN v2.7 here:</p>
<p><a href="http://27.106.13.152/w/winAUTOPWN_2.7.RAR">winAUTOPWN_2.7.RAR</a></p>
<p>Or read more <a href="http://winautopwn.co.nr">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3085+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;t=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fwinautopwn-v2-7-released-windows-autohacking-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Windows Binary Planting DLL Preloading/Hijacking Bug</title>
		<link>http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/</link>
		<comments>http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 09:05:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[binary planting]]></category>
		<category><![CDATA[dll bug]]></category>
		<category><![CDATA[dll hijacking]]></category>
		<category><![CDATA[dll loading]]></category>
		<category><![CDATA[dll pre-loading]]></category>
		<category><![CDATA[dll preloading]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[malware dll]]></category>
		<category><![CDATA[windows binary planting]]></category>
		<category><![CDATA[windows dll bug]]></category>
		<category><![CDATA[windows dll preloading bug]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2935</guid>
		<description><![CDATA[The big news that is turning the infosec world inside out this week is about a new DLL pre-loading/hijacking bug which effects more than 200 Windows applications including some produced by Microsoft itself. The basis of this exploit is the way in which Windows works and how it loads DLL files used by many applications, [...]]]></description>
			<content:encoded><![CDATA[<p>The big news that is turning the infosec world inside out this week is about a new DLL pre-loading/hijacking bug which effects more than 200 <a href="http://www.darknet.org.uk/tag/windows/">Windows</a> applications including some produced by <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> itself.</p>
<p>The basis of this exploit is the way in which Windows works and how it loads DLL files used by many applications, if an application calls a DLL without specifying an absolute path Windows will conduct a search for the DLL file in various set locations. This of course can and is being abused.</p>
<p>The big problem with is the fact that it can&#8217;t really be patched by Microsoft, each vulnerable application vendor needs to issue an update to their applications to fix the way in which they deal with DLL files.</p>
<p>The Microsoft Security Response Center has written about the issue here:</p>
<blockquote><p>Loading dynamic libraries is basic behavior for Windows and other operating systems, and the design of some applications require the ability to load libraries from the current working directory. Hence, this issue cannot directly be addressed in Windows without breaking expected functionality. Instead, it requires developers to ensure they code secure library loads. However, we’re looking into ways to make it easier for developers to not make this mistake in the future.</p>
<p>Microsoft is also conducting a thorough investigation into how this new vector may affect Microsoft products.  As always, if we find this issue affects any of our products, we will address them appropriately.</p></blockquote>
<p><a href="http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx">More information about the DLL Preloading remote attack vector</a></p>
<p>Microsoft also has published some Registry tweaks which can change the default DLL library search behaviour (downloads are available for each version of Windows):</p>
<p><a href="http://support.microsoft.com/kb/2264107">A new CWDIllegalInDllSearch registry entry is available to control the DLL search path algorithm</a></p>
<p>Microsoft and quite a few other researchers have known about this for some time and have stated they won&#8217;t be patching it but will be looking at ways to address it in future versions of Windows.</p>
<blockquote><p>MIcrosoft has told a researcher that it won&#8217;t patch a problem that has left scores of Windows applications open to attack. According to a growing number of reports, crucial Windows functionality has been misused by countless developers, including Microsoft&#8217;s, leaving a large number of Windows programs vulnerable to attack because of the way they load components.</p>
<p>The issue first surfaced last week when HD Moore, chief security officer of Rapid7 and creator of the open-source Metasploit hacking toolkit, said he had found 40 vulnerable applications , including the Windows shell. A day later, Slovenian security firm Acros announced its homegrown tool had uncovered more than 200 flawed Windows programs in an investigation that began in November 2008.</p>
<p>Over the weekend, Taeho Kwon, a Ph.D. candidate in computer science at the University of California Davis, stepped forward to cite his research, which he published in a February 2010 paper. </p></blockquote>
<p><a href="http://www.networkworld.com/news/2010/082310-microsoft-wont-patch-critical-dll.html?source=nww_rss">Microsoft won&#8217;t patch critical DLL loading bugs </a></p>
<p>The attack code was posted yesterday to the <a href="http://www.exploit-db.com/">Exploit Database</a>. It included exploits for the Wireshark packet sniffer, Windows Live email and Microsoft MovieMaker, in addition to those for the most recent versions of Firefox, uTorrent and PowerPoint.</p>
<p>Some more info is available here:</p>
<p><a href="http://www.networkworld.com/news/2010/082410-microsoft-binary-planting-bug-what.html?source=nww_rss">Microsoft Binary Planting Bug: What You Need to Know</a></p>
<p>If you want to scan your own system you can do so here:</p>
<p><a href="http://blog.metasploit.com/2010/08/better-faster-stronger.html">DLLHijackAuditKit v2</a></p>
<p>It includes complete instructions and the steps to scan for vulnerable apps, build test cases for each application and assemble an exploit.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Windows+Binary+Planting+DLL+Preloading%2FHijacking+Bug+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2935+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/&amp;t=Windows+Binary+Planting+DLL+Preloading%2FHijacking+Bug" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/&amp;title=Windows+Binary+Planting+DLL+Preloading%2FHijacking+Bug" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/&amp;title=Windows+Binary+Planting+DLL+Preloading%2FHijacking+Bug" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/&amp;title=Windows+Binary+Planting+DLL+Preloading%2FHijacking+Bug" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/&amp;title=Windows+Binary+Planting+DLL+Preloading%2FHijacking+Bug" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F08%2Fwindows-binary-planting-dll-preloadinghijacking-bug%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/08/windows-binary-planting-dll-preloadinghijacking-bug/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft Confirms Windows Zero Day Bug In Shortcut Files</title>
		<link>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/</link>
		<comments>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 09:51:55 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0-day windows exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[windows shortcut exploit]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows xp sp2]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2804</guid>
		<description><![CDATA[This is a pretty nasty attack and for once Microsoft have actually acknowledged and confirmed this is a critical unpatched vulnerability. Incidentally Microsoft also recently retired Windows XP SP2 from the support cycle, and this vulnerability effects that system and they have stated they will not be patching it. It&#8217;s a pretty serious bug and [...]]]></description>
			<content:encoded><![CDATA[<p>This is a pretty nasty attack and for once <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> have actually acknowledged and confirmed this is a critical unpatched vulnerability. Incidentally Microsoft also recently retired Windows XP SP2 from the support cycle, and this vulnerability effects that system and they have stated they will not be patching it.</p>
<p>It&#8217;s a pretty serious bug and it seems hackers have been maliciously exploiting it in the wild for over a month. The Stuxnet malware has been using this vulnerability to gain access to machines then download further attack files including a <a href="http://www.darknet.org.uk/tag/root-kit/">root kit</a>.</p>
<blockquote><p>Microsoft on Friday warned that attackers are exploiting a critical unpatched Windows vulnerability using infected USB flash drives.</p>
<p>The bug admission is the first that affects Windows XP Service Pack 2 (SP2) since Microsoft retired the edition from support , researchers said. When Microsoft does fix the flaw, it will not be providing a patch for machines still running XP SP2. In a security advisory , Microsoft confirmed what other researchers had been saying for almost a month: Hackers have been exploiting a bug in Windows &#8220;shortcut&#8221; files, the placeholders typically dropped on the desktop or into the Start menu to represent links to actual files or programs.</p>
<p>&#8220;In the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware,&#8221; Dave Forstrom, a director in Microsoft&#8217;s Trustworthy Computing group, said in a post Friday to a company blog . Stuxnet is a clan of malware that includes a Trojan horse that downloads further attack code, including a rootkit that hides evidence of the attack.</p>
<p>Forstrom characterized the threat as &#8220;limited, targeted attacks,&#8221; but the Microsoft group responsible for crafting antivirus signatures said it had tracked 6,000 attempts to infect Windows PCs as of July 15. </p></blockquote>
<p>Limited but targeted attacks are the worst kind as they can really burrow through corporate defenses. A lot of companies are taking this seriously, including all the main players in the anti-virus arena.</p>
<p>You have to wonder if Microsoft will break their <a href="http://www.darknet.org.uk/tag/patch-tuesday/">patch tuesday</a> policy and issue an emergency <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-band patch</a> for this.</p>
<p>Especially since <a href="http://www.networkworld.com/news/2010/072310-virus-writers-are-picking-up.html?source=nww_rss">more virus writers are picking up on this flaw</a> meaning it&#8217;s becoming more widespread.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<blockquote><p>On Friday, Siemens alerted customers of its Simatic WinCC management software that attacks using the Windows vulnerability were targeting computers used to manage large-scale industrial control systems used by major manufacturing and utility companies. The vulnerability was first mentioned on June 17 in an alert issued by VirusBlokAda , a little-known security firm based in Belarus. Other security organizations, including U.K.-based Sophos and SANS Institute&#8217;s Internet Storm Center , picked up on the threat Friday. Security blogger Brian Krebs , formerly with the Washington Post, reported on it Thursday.</p>
<p>According to Microsoft, Windows fails to correctly parse shortcut files, identified by the &#8220;.lnk&#8221; extension. The flaw has been exploited most frequently using USB flash drives. By crafting a malicious .lnk file, hackers can hijack a Windows PC with little user interaction: All that&#8217;s necessary is that the user views the contents of the USB drive with a file manager like Windows Explorer.</p>
<p>Chester Wisniewski, a senior security advisory with Sophos, called the threat &#8220;nasty,&#8221; and said his tests showed that the exploit works even when AutoRun and AutoPlay &#8212; two functions that have previously been used by attackers to commandeer PCs using infected flash drives &#8212; are disabled. The rootkit also bypasses all security mechanisms in Windows, including the User Account Control (UAC) prompts in Vista and Windows 7 , said Wisniewski in a blog entry Friday. </p></blockquote>
<p>I&#8217;m sure they&#8217;ll come up with some reason for not patching this sooner rather than later. The scary part is the attack can still be carried out even if AutoRun and AutoPlay are disabled.</p>
<p>The rootkit also bypasses the security mechanisms in Windows 7 and Vista making this a very dangerous attack.</p>
<p>You can find a temporary workaround in the Microsoft Security Advisory here:</p>
<p><a href="http://support.microsoft.com/kb/2286198">Microsoft Security Advisory: Vulnerability in Windows Shell could allow remote code execution</a></p>
<p>And Microsoft has stated they are working on a patch.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/071710-microsoft-confirms-nasty-windows-zero-day.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2804+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;t=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Fmicrosoft-confirms-windows-zero-day-bug-in-shortcut-files%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Argument Switch Attack Bypasses Windows Security Software</title>
		<link>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/</link>
		<comments>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/#comments</comments>
		<pubDate>Wed, 12 May 2010 10:47:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[argument switch]]></category>
		<category><![CDATA[argument switch attack]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[bypass anti-virus]]></category>
		<category><![CDATA[bypass antivirus]]></category>
		<category><![CDATA[bypass av]]></category>
		<category><![CDATA[bypass windows security software]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[immunet]]></category>
		<category><![CDATA[kernel mode drivers]]></category>
		<category><![CDATA[matousec]]></category>
		<category><![CDATA[matousec.com]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[trend micro]]></category>
		<category><![CDATA[windows kernel exploit]]></category>
		<category><![CDATA[windows kernel hook]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2691</guid>
		<description><![CDATA[There&#8217;s been a lot of highly technical and most theoretical attacks lately, academic season really is in full swing. This is a very neat attack which is being labeled somewhere between catastrophic and mildly annoying depending on who you ask. It effects most of the major Anti-virus vendors, it&#8217;s called an argument-switch attack and leverages [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There&#8217;s been a lot of highly technical and most theoretical attacks lately, academic season really is in full swing. This is a very neat attack which is being labeled somewhere between catastrophic and mildly annoying depending on who you ask.</p>
<p>It effects most of the major Anti-virus vendors, it&#8217;s called an argument-switch attack and leverages on the way in which most anti-viral suites interact with the Windows kernel.</p>
<p>It seems to be most critical on Windows XP which is an operating system near the end of life anyway, so it shouldn&#8217;t be too widespread &#8211; that&#8217;s even assuming the bad guys can work it out and spread it in the wild (I would safely assume they can). Although the research does indicate it also works on Vista SP1.</p>
<blockquote><p>A just-published attack tactic that bypasses the security protections of most current antivirus software is a &#8220;very serious&#8221; problem, an executive at one unaffected company said today.</p>
<p>Last Wednesday, researchers at Matousec.com outlined how attackers could exploit the kernel driver hooks that most security software use to reroute Windows system calls through their software to check for potential malicious code before it&#8217;s able to execute. Calling the technique an &#8220;argument-switch attack,&#8221; a Matousec-written paper spelled out in relatively specific terms how an attacker could swap out benign code for malicious code between the moments when the security software issues a green light and the code actually executes.</p>
<p>&#8220;This is definitely very serious,&#8221; said Alfred Huger, vice president of engineering at Immunet, a Palo Alto, Calif.-based antivirus company. &#8220;Probably any security product running on Windows XP can be exploited this way.&#8221; Huger added that Immunet&#8217;s desktop client is not vulnerable to the argument-switch attacks because the company&#8217;s software uses a different method to hook into the Windows kernel. </p></blockquote>
<p>Some of the AV vendors are using different methods to communicate with the Windows kernel, so aren&#8217;t vulnerable to this attack &#8211; such as Immunet. I hope the collective AV companies pull their fingers out and do some real testing on this attack to see if it can really impact consumers or not.</p>
<p>What we really don&#8217;t need is &#8220;Oh it&#8217;s really complex and unlikely, it&#8217;s not a big deal&#8221; &#8211; then later 200,000 machines get owned using the technique. At least they know about and can perhaps address the sloppy methods they are using to implement kernel hooks.</p>
<blockquote><p>According to Matousec, nearly three-dozen Windows desktop security titles, including ones from Symantec, McAfee, Trend Micro, BitDefender, Sophos and others, can be exploited using the argument-switch tactic. Matousec said it had tested the technique on Windows XP SP3 and Vista SP1 on 32-bit machines.</p>
<p>Some security vendors agreed with Huger. &#8220;It&#8217;s a serious issue and Matousec&#8217;s technical findings are correct,&#8221; said Mikko Hypponen, chief research officer at Finnish firm F-Secure, in an e-mail.</p>
<p>&#8220;Matousec&#8217;s research is absolutely important and significant in the short term,&#8221; echoed Rik Ferguson, a senior security advisor at Trend Micro, in a blog post earlier Monday.</p>
<p>Other antivirus companies downplayed the threat, however. &#8220;Based on our initial review of the public documentation, we believe this is a complicated attack with several mitigating factors that make it unlikely to be a viable, real world, widespread attack scenario,&#8221; a McAfee spokesman said in an e-mail reply to a request for comment. &#8220;The attack would require some level of existing access to the target computer, as the attack described by Matousec does not on its own bypass security software or allow malware to run.&#8221;</p>
<p>Kaspersky Lab had a similar reaction. &#8220;[We] have analyzed the published material and concluded that the issue is only linked to certain features of [our] products,&#8221; Kaspersky said in an e-mailed statement. &#8220;Kaspersky Lab products implement not only [kernel] hooks, but a wide range of technologies, including secure sandboxing and other methods of restricting suspicious kernel mode activity.&#8221; </p></blockquote>
<p>I guess most AV companies don&#8217;t go that deep into system security, to the point of exploring how they implement kernel addressing and hooks to enable their software to function. Either way the research is now published, is picking up quite a bit of press and that itself is likely to force some action.</p>
<p>The full paper is available with details of the attack from Matousec here:</p>
<p><a href="http://www.matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php">KHOBE – 8.0 earthquake for Windows desktop security software</a></p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2010/051110-new-attack-tactic-sidesteps-windows.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=New+Argument+Switch+Attack+Bypasses+Windows+Security+Software+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2691+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/&amp;t=New+Argument+Switch+Attack+Bypasses+Windows+Security+Software" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/&amp;title=New+Argument+Switch+Attack+Bypasses+Windows+Security+Software" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/&amp;title=New+Argument+Switch+Attack+Bypasses+Windows+Security+Software" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/&amp;title=New+Argument+Switch+Attack+Bypasses+Windows+Security+Software" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/&amp;title=New+Argument+Switch+Attack+Bypasses+Windows+Security+Software" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fnew-argument-switch-attack-bypasses-windows-security-software%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Confirms First Windows 7 0-Day Vulnerability</title>
		<link>http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 10:29:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[smb exploit]]></category>
		<category><![CDATA[smb flaw]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows 7]]></category>
		<category><![CDATA[windows 7 0day]]></category>
		<category><![CDATA[windows 7 exploit]]></category>
		<category><![CDATA[windows 7 oday]]></category>
		<category><![CDATA[windows 7 security]]></category>
		<category><![CDATA[windows 7 vulnerability]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2291</guid>
		<description><![CDATA[So a pretty serious remote vulnerability has been discovered in Windows 7, as usual Microsoft is downplaying the problem asking you to block the ports on your firewall rather than fixing the issue. I&#8217;d imagine the problem would only really be a big issue inside networks as who exposes SMB ports to the outside world [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So a pretty serious remote vulnerability has been discovered in Windows 7, as usual Microsoft is downplaying the problem asking you to block the ports on your firewall rather than fixing the issue.</p>
<p>I&#8217;d imagine the problem would only really be a big issue inside networks as who exposes SMB ports to the outside world anyway (TCP ports 139 and 445).</p>
<p>But as we all know, the biggest threat to corporate network security ALWAYS comes from the inside.</p>
<blockquote><p>Microsoft late on Friday confirmed that an unpatched vulnerability exists in Windows 7, but downplayed the problem, saying most users would be protected from attack by blocking two ports at the firewall.</p>
<p>In a security advisory , Microsoft acknowledged that a bug in SMB (Server Message Block), a Microsoft-made network file- and print-sharing protocol, could be used by attackers to cripple Windows 7 and Windows </p>
<p>The zero-day vulnerability was first reported by Canadian researcher Laurent Gaffie last Wednesday, when he revealed the bug and posted proof-of-concept attack code to the Full Disclosure security mailing list and his blog. According to Gaffie, exploiting the flaw crashes Windows 7 and Server 2008 R2 systems so thoroughly that the only recourse is to manually power off the computers.</p>
<p>At the time, Microsoft only said it was investigating Gaffie&#8217;s reports.</p></blockquote>
<p>And well let&#8217;s face is, this is not the first time that a serious flaw that can be remotely exploited has been discovered in SMB.</p>
<p>It doesn&#8217;t seem like the most secure of protocols, I really doubt Microsoft developed it using SDL (Security Development Lifecycle).</p>
<p>It seems in this case though it&#8217;s limited to a DoS attack, perhaps due to all the fancy security controls Microsoft has implemented in the Windows 7 kernel.</p>
<blockquote><p>Then on Friday, it took the next step and issued the advisory. &#8220;Microsoft is aware of public, detailed exploit code that would cause a system to stop functioning or become unreliable,&#8221; Dave Forstrom, a spokesman for Microsoft security group, said in an e-mail. &#8220;The company is not aware of attacks to exploit the reported vulnerability at this time.&#8221;</p>
<p>Forstrom echoed Gaffie&#8217;s comments earlier in the week that while an exploit could incapacitate a PC, the vulnerability could not be used by hackers to install malicious code on a Windows 7 system.</p>
<p>Both SMBv1 and its successor, SMBv2, contain the bug. &#8220;Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and Windows 2000 are not affected,&#8221; assured Forstrom.</p>
<p>Attacks could be aimed at any browser, not just Internet Explorer (IE), Microsoft warned. After tricking users into visiting a malicious site or a previously-compromised domain, hackers could feed them specially-crafted URIs (uniform resource identifier), and then crash their PCs with malformed SMB packets. </p></blockquote>
<p>Even so, I&#8217;m sure a skilled attacker could probably work out a way to drop some malicious code into the OS using this PoC and well if I know the underground they probably already are.</p>
<p>This vulnerability is the first official zero-day reported and confirmed by Microsoft in Windows 7 since the new operating system went on sale October 22nd.</p>
<p>I&#8217;m sure there will be many more.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/111409-microsoft-confirms-first-windows-7.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Confirms+First+Windows+7+0-Day+Vulnerability+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2291+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/&amp;t=Microsoft+Confirms+First+Windows+7+0-Day+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/&amp;title=Microsoft+Confirms+First+Windows+7+0-Day+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/&amp;title=Microsoft+Confirms+First+Windows+7+0-Day+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/&amp;title=Microsoft+Confirms+First+Windows+7+0-Day+Vulnerability" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/&amp;title=Microsoft+Confirms+First+Windows+7+0-Day+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F11%2Fmicrosoft-confirms-first-windows-7-0-day-vulnerability%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/microsoft-confirms-first-windows-7-0-day-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>No Emergency Patch For Latest Windows Exploit</title>
		<link>http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/</link>
		<comments>http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 07:17:48 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploit windows]]></category>
		<category><![CDATA[hack windows]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[redmond]]></category>
		<category><![CDATA[smb 2]]></category>
		<category><![CDATA[smb exploit]]></category>
		<category><![CDATA[smb negotiate function]]></category>
		<category><![CDATA[smb2]]></category>
		<category><![CDATA[smb2 exploit]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>
		<category><![CDATA[windows-vista]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2149</guid>
		<description><![CDATA[Another reason for Windows users to hate the Microsoft Patch Tuesday policy, The exploit isn&#8217;t 100% reliable but it&#8217;s still fairly significant in my eyes as it is a critical vulnerability and can be used for code execution. Vista isn&#8217;t the most popular OS still so perhaps Microsoft don&#8217;t the threat being that wide as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Another reason for Windows users to hate the <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> <a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a> policy, </p>
<p>The exploit isn&#8217;t 100% reliable but it&#8217;s still fairly significant in my eyes as it is a critical vulnerability and can be used for code execution.</p>
<p>Vista isn&#8217;t the most popular OS still so perhaps Microsoft don&#8217;t the threat being that wide as the protocol this exploit focuses on (SMB 2) was only introducted in Vista.</p>
<blockquote><p>A security researcher has downplayed the significance of publicly released attack code exploiting a critical vulnerability in newer versions of Windows, saying it isn&#8217;t reliable enough to force Microsoft to issue an emergency patch.</p>
<p>The exploit, which on Monday was folded into the open-source Metasploit penetration testing kit, is at best successful only 50 percent of the time, said Dave Aitel, CTO of security firm Immunity. Given the burden of releasing out-of-schedule patches, Microsoft is unlikely to do so in this case.</p>
<p>&#8220;To move something like Microsoft you&#8217;ve got to have something major and this isn&#8217;t quite it,&#8221; Aitel, whose company released its own attack code two weeks ago. &#8220;It&#8217;s going to be a lot of work to take the exploit where it is to something that works enough that they will do that.&#8221;</p></blockquote>
<p>It seems like the exploit is more reliable with Windows on VMware, but honestly how commonly do you see that? With a real native Windows installation they are only seeing a 10% success rate.</p>
<p>Which really isn&#8217;t that serious is it?</p>
<p>Apparently Immunity have made it much more reliable, but they have poured a ton of resources into it.</p>
<blockquote><p>The vulnerability, which surfaced three weeks ago, resides in file-sharing technology called SMB2, short for server message block version 2, which was first added to Windows Vista and later made its way into newer versions of the operating system. While the Metasploit exploit is sophisticated, it is frequently thwarted by a security measure known as ASLR. Short for address space layout randomization, it picks a different memory location to load system components each time the OS is started.</p>
<p>Without being able to predict where required code will be located, the Metasploit attack isn&#8217;t reliable enough to prompt Microsoft to take the drastic step of releasing a patch outside of the regularly scheduled update cycle. The software giant adopted the patch routine to make life easier on system administrators by allowing them to plan and test updates before installing them on huge numbers of business critical machines.</p>
<p>The Metasploit exploit in many cases is able to get around ASLR by targeting memory locations that are predictable when Windows is running on VMware. But when the exploit targets the OS running directly on a computer, the success rate can be as low as 10 percent.</p></blockquote>
<p>Microsoft will patch this eventually, but I doubt it&#8217;ll be soon and they definitely won&#8217;t be rushing an out-of-schedule patch out just for this vulnerability.</p>
<p>The question is can the bad guys fashion this into a reliable exploit and get some major ownage going on?</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/09/29/windows_vista_exploit_released/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=No+Emergency+Patch+For+Latest+Windows+Exploit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2149+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/&amp;t=No+Emergency+Patch+For+Latest+Windows+Exploit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/&amp;title=No+Emergency+Patch+For+Latest+Windows+Exploit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/&amp;title=No+Emergency+Patch+For+Latest+Windows+Exploit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/&amp;title=No+Emergency+Patch+For+Latest+Windows+Exploit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/&amp;title=No+Emergency+Patch+For+Latest+Windows+Exploit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F10%2Fno-emergency-patch-for-latest-windows-exploit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/no-emergency-patch-for-latest-windows-exploit/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hackers Exploiting Unpatched DirectX Bug With Quicktime</title>
		<link>http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/</link>
		<comments>http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 10:41:21 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[directx exploit]]></category>
		<category><![CDATA[directx vulnerability]]></category>
		<category><![CDATA[hacking directshow]]></category>
		<category><![CDATA[hacking directx]]></category>
		<category><![CDATA[hacking microsoft]]></category>
		<category><![CDATA[hacking quicktime]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft windows]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1826</guid>
		<description><![CDATA[It seems like another fairly critical flaw has been discovered in Microsoft Windows. It&#8217;s serious as it allows remote code execution, which basically means if you get hit with it your machine is owned. It seems DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk. Windows Vista, Server 2008 [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems like another fairly critical flaw has been discovered in <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> Windows. It&#8217;s serious as it allows remote code execution, which basically means if you get hit with it your machine is owned.</p>
<p>It seems DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk. Windows Vista, Server 2008 and Windows 7 are not effected &#8211; so they have fixed the problem at some point in their development cycle, they just haven&#8217;t pushed it back to the older operating systems yet.</p>
<blockquote><p>For the third time in the last 90 days, Microsoft Corp. has warned that hackers are exploiting an unpatched critical vulnerability in its software.</p>
<p>Late Thursday, Microsoft issued a security advisory that said malicious hackers were already using attack code that leveraged a bug in DirectX, a Windows subsystem crucial to games and used when streaming video from Web sites.</p>
<p>Hackers are using malicious QuickTime files &#8212; QuickTime is rival Apple Inc.&#8217;s default video format &#8212; to hijack PCs, Microsoft said. &#8220;The vulnerability could allow remote code execution if [the] user opened a specially crafted QuickTime media file,&#8221; the company said in the advisory. &#8220;Microsoft is aware of limited, active attacks that use this exploit code.&#8221;</p>
<p>According to Christopher Budd, a spokesman for the Microsoft Security Response Center, QuickTime itself is not flawed. Instead, the QuickTime parser in DirectShow, a component of DirectX, contains the bug. &#8220;An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in e-mail,,&#8221; Budd said in an entry on the MSRC blog.</p></blockquote>
<p>Microsoft has had quite a spate of serious vulnerabilities recently, it seems resourceful hackers are targeting applications and components of the OS rather than the actual OS or networking stack.</p>
<p>Which makes sense, you&#8217;d expect the actual OS to be fairly secure now and not attention has been paid to those &#8216;must-have&#8217; system softwares like DirectX.</p>
<blockquote><p>Because the bug is in DirectShow, any browser using a plug-in that relies on DirectShow is also vulnerable.</p>
<p>DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk, Budd said, but Vista, Server 2008 and Windows 7 are not. &#8220;Our investigation has shown that the vulnerable code was removed as part of our work building Windows Vista,&#8221; Budd said.</p>
<p>Until a patch is available, users can protect their PCs by disabling QuickTime parsing. To do that requires editing the Windows registry, normally a task most users shy from, but Microsoft has automated the workaround. &#8220;We&#8217;ve gone ahead and built a &#8216;Fix it&#8217; that implements the &#8216;Disable the parsing of QuickTime content in quartz.dll&#8217; registry change,&#8221; Budd said. &#8220;We have also built a &#8216;Fix it&#8217; that will undo the workaround automatically.&#8221; </p></blockquote>
<p>Watch out when you are opening video files from unknown sources, especially in e-mail attachments (even from known sources) and you can use the &#8216;Fix it&#8217; to mitigate against the problem until the patch is released.</p>
<p><a href="http://support.microsoft.com/kb/971778">Microsoft Security Advisory: Vulnerability in Microsoft DirectShow could allow remote code execution</a></p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/052909-hackers-exploit-unpatched-windows.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1826+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;t=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fhackers-exploiting-unpatched-directx-bug-with-quicktime%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>winAUTOPWN &#8211; Windows Autohacking Tool</title>
		<link>http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/</link>
		<comments>http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 07:56:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[automated exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[winautopwn]]></category>
		<category><![CDATA[windows-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1664</guid>
		<description><![CDATA[winAUTOPWN is a TooL to Autohack your targets with least possible interaction. The aim of creating winAUTOPWN is not to compete with already existing commercial frameworks like Core Impact (Pro), Immunity Canvas, Metasploit Framework (freeware), etc. which offer autohacks, but to create a free, quick, standalone application which is easy to use and doesn&#8217;t require [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>winAUTOPWN is a TooL to Autohack your targets with least possible interaction. The aim of creating winAUTOPWN is not to compete with already existing commercial frameworks like Core Impact (Pro), Immunity Canvas, Metasploit Framework (freeware), etc. which offer autohacks, but to create a free, quick, standalone application which is easy to use and doesn&#8217;t require a lot of support of other dependencies.</p>
<p>Also not forgetting that winAUTOPWN unlike other frameworks maintains the original exploit writer&#8217;s source code intact just as it was and uses it. This way the exploit writer&#8217;s credit and originality is maintained. The source is modified only when required to enable a missing feature or to remove hard-coded limitations. Under these circumstances also, the exploit writers credits remain intact.</p>
<p>Newer exploit modules are added as and when they release and older ones are also being daily added.<br />
Binaries of perl, php, python and cygwin DLLs (included) are required to exist either in a common folder or should be properly installed with their paths registered for those exploits which are cannot be compiled into a PE-exe. </p>
<p>Features :</p>
<ul>
<li>Contains already custom-compiled executables of famous and effective exploits alongwith a few original modified exploits.</li>
<li>No need to debug, script or compile the source codes.</li>
<li>Scans all ports 1 &#8211; 65535 after taking the IP address and tries all possible exploits according to the list of discovered open ports (OpenPorts.TXT)</li>
<li>PortScan is multi-threaded.</li>
<li>Doesn&#8217;t require any Database like (PostGres,MySQL,etc.) at the back-end</li>
<li>Can be also be used to test effectiveness of IDS/IPS</li>
<li>Launched exploits are independent and doesn&#8217;t rely on service fingerprinting (to avoid evasion, if any)</li>
<li>Requires presence of php, perl and python with registeredpaths in Environment variables.</li>
</ul>
<p>winAUTOPWN is updated almost daily. A separate DragonflyBSD-server is being set up which will hold the exploit repository and the next version will autosync the exploits from them in the appropriate folder. </p>
<p>You can download winAUTOPWN here:</p>
<p><a href="http://winautopwn.exofire.net/winAUTOPWN.RAR">winAUTOPWN.RAR</a></p>
<p></p>
<p>Or read more <a href="http://winautopwn.co.nr">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=winAUTOPWN+%E2%80%93+Windows+Autohacking+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1664+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/&amp;t=winAUTOPWN+%E2%80%93+Windows+Autohacking+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/&amp;title=winAUTOPWN+%E2%80%93+Windows+Autohacking+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/&amp;title=winAUTOPWN+%E2%80%93+Windows+Autohacking+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/&amp;title=winAUTOPWN+%E2%80%93+Windows+Autohacking+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/&amp;title=winAUTOPWN+%E2%80%93+Windows+Autohacking+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F04%2Fwinautopwn-windows-autohacking-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Serious Exploit in Windows Media Player (WMP)</title>
		<link>http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/</link>
		<comments>http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/#comments</comments>
		<pubDate>Fri, 05 Jan 2007 04:30:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-media-player]]></category>
		<category><![CDATA[windows-media-player-exploit]]></category>
		<category><![CDATA[wmp-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/</guid>
		<description><![CDATA[Oh look! Another 0-day in Windows&#8230;this time in Media Player, there was a few in Word lately and the latest thing that just hit is an XSS flaw in PDF files online. I&#8217;ll report more on those later. The Windows Media Player library WMVCORE.DLL contains a potentially exploitable heap buffer overflow in its handling of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Oh look! Another 0-day in Windows&#8230;this time in Media Player, there was a few in Word lately and the latest thing that just hit is an XSS flaw in PDF files online.</p>
<p>I&#8217;ll report more on those later.</p>
<blockquote><p>The Windows Media Player library WMVCORE.DLL contains a potentially exploitable heap buffer overflow in its handling of &#8220;REF HREF&#8221; URLs within ASX files. If the URL contains an unrecognized protocol (only &#8220;file&#8221;, &#8220;ftp&#8221;, &#8220;http&#8221;, &#8220;https&#8221;, &#8220;mms&#8221;, &#8220;mmst&#8221;, &#8220;mmsu&#8221;, &#8220;rtsp&#8221;, &#8220;rtspt&#8221;, and &#8220;rtspu&#8221; appear to be recognized), the function at 7D7A8F27 in WMVCORE.DLL version 9.0.0.3250, and at 086E586E in WMVCORE.DLL version 10.0.0.3802, will create a copy of the string in which the protocol is replaced with &#8220;mms&#8221;. A heap buffer is allocated, the string &#8220;mms&#8221; is copied into it, and then everything after and including &#8220;://&#8221; in the &#8220;REF HREF&#8221; URL is concatenated using wcsncat.</p></blockquote>
<p>So what out what you are streaming..please! Or alternatively use something decent like Winamp.</p>
<blockquote><p>Unfortunately, the heap buffer for the new &#8220;mms&#8221; URL is allocated to the size of the &#8220;REF HREF&#8221; URL, and even more unfortunately, the length of the input string being passed to wcsncat is supplied as the character count, effectively causing wcsncat to behave identically to wcscat. As a result, a two- or four-byte heap overflow is possible if the &#8220;REF HREF&#8221; URL features a protocol shorter than three characters (the length of &#8220;mms&#8221;).</p>
<p>Single-letter protocols (such as &#8220;a://&#8221;) are rejected, but this restriction can be circumvented by encoding the protocol (&#8220;%61://&#8221;), thereby making a four-byte overflow possible.</p>
<p>Exploitability due to the corruption of the adjacent heap block&#8217;s header is assumed likely but research is ongoing.</p></blockquote>
<p>As far as I know there&#8217;s no current exploit for this, but it is a possibility.</p>
<p></p>
<p>Source: <a href="http://research.eeye.com/html/alerts/zeroday/20061122.html">eEye</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Serious+Exploit+in+Windows+Media+Player+%28WMP%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D411+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;t=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fserious-exploit-in-windows-media-player-wmp%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

