ZeroPaid.com

  (#1) Old
Crazy Horse Offline
ZP Troll SWAT Team
Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000
 
Crazy Horse's Avatar
 
Posts: 3,956
Join Date: Apr 2002
Location: Northern California
Age: 55
Reputation Power: 318
An alert for XP users - September 12th, 2002, 12:56 AM

I found this information out. Read carefully:
A malicious Win-XP Help Center request can easily and silently delete the contents of any directory on your Windows machine, we've learned. Worse, MS has rolled the fix silently into SP1 without making a public announcement. A good sketch of the problem in English, along with a harmless self-test, can be found here, thanks to Mike at http://unity.skankhouse.org, who did some tinkering after noticing a tip on a BBS.

Another, slightly earlier, mention comes from VSAntivirus, but the page, unfortunately, is en espanol, though there are some handy screen shots in their bulletin.

The hole was discovered by Shane Hird of Distributed Systems Technology Centre, who first reported it to MS on 25 June 2002. His bulletin, dated 15 August, offers the most detailed view of the problem. He suggests that fellow bug hunters look more deeply into the Help Center and its mysterious powers, since requests can remotely open files with elevated privileges. He offers a few hints about where one might start probing.


Quote:
--------------------------------------------------------------------------------
To verify the exploit all you need to do is pop the following request into any address bar (IE, Win Explorer, etc): hcp://system/DFS/uplddrvinfo.htm?file://c:\test\* and the directory 'test' will be emptied after a couple of Help Center 'wizard' pages pop up uselessly to distract you.
--------------------------------------------------------------------------------



The example works as advertised, so anyone wanting to play with it should create a test directory with copies of files. Of course you can delete your entire root directory with this approach if you so choose. Or someone else's.

The exploit is extremely dangerous because it looks to the casual user just like a URL, and can be sent in an e-mail or set up as a link on a Web page. Promising heaps of free pr0n in a busy IRC channel would also likewise be effective.

To get rid of the vulnerability, you have two choices. You can install XP's new SP1, which will give Billg remote root privileges on your box by virtue of his new, Trojan EULA (and silently re-enable some services you may have disabled like 'automatic update'); or you can just go to C:\Windows\PCHEALTH\HELPCTR\SYSTEM\DFS\ and find the file uplddrvinfo.htm. This you can simply delete or rename. But beware of installing MS patches later on: these have a funny tendency to restore files and settings outside their immediate purview, back to Redmond defaults.

To check it out I did a clean install of XP and verified the exploit on a virgin image. I then installed all of the XP patches and updates except SP1, and it still worked. So SP1 is the only 'official' means of fixing the hole. It's not otherwise been dealt with. Those who object to the SP1 EULA on moral grounds will have to delete or rename uplddrvinfo.htm, and do a search for it after subsequent patching to verify that it's still gone.

Problems with the XP Help Center have been known for some time, at least since November 2001, when this exploitable buffer overflow was first reported. Now the issue has finally been fixed, in the background, with no announcement from Redmond. This means that any XP user who doesn't install SP1, and who never hears of the flaw, will remain vulnerable.

Redmond's handling of the issue is appalling. Apparently, 'Trustworthy Computing' means never having to say you screwed up.

We recommend installing SP1 to avoid getting effected/hit by malicious webpages/e-mails and the various other forms of expolits. Also installing and using a Virus Checker on your system would help to lessen the risk of getting hit.


May you always run with the wind at your back and good friends by your side.
Mitakuye Oyasin (All My Relations-We are All Related)

Other places you can find me at:
Slyck
P2PConsortium
Beat King
Napsterites
PCTechTalk

"Fear can hold you prisoner, hope can set you free."

"I guess it comes down
to a simple choice, really. Get
busy living or get busy dying."

(Both quotes from Shawshank Redemption)
   
Reply With Quote
  (#2) Old
Crazy Horse Offline
ZP Troll SWAT Team
Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000Crazy Horse Reputation is 2000
 
Crazy Horse's Avatar
 
Posts: 3,956
Join Date: Apr 2002
Location: Northern California
Age: 55
Reputation Power: 318
SP1.... - September 12th, 2002, 01:00 AM

And you already know the problems related to the service patch.


May you always run with the wind at your back and good friends by your side.
Mitakuye Oyasin (All My Relations-We are All Related)

Other places you can find me at:
Slyck
P2PConsortium
Beat King
Napsterites
PCTechTalk

"Fear can hold you prisoner, hope can set you free."

"I guess it comes down
to a simple choice, really. Get
busy living or get busy dying."

(Both quotes from Shawshank Redemption)
   
Reply With Quote
  (#3) Old
mojo-ris-in Offline
Kneel Before Zod......ZOD
mojo-ris-in Reputation 350mojo-ris-in Reputation 350mojo-ris-in Reputation 350mojo-ris-in Reputation 350mojo-ris-in Reputation 350
 
mojo-ris-in's Avatar
 
Posts: 1,277
Join Date: May 2002
Location: Texas
Age: 42
Reputation Power: 159
Thumbs up Thanks Crazy Horse - September 12th, 2002, 06:04 AM

:devil Thanks Crazy good job I took SP1 update sheesh is it big! It took over an hour to DL and install.


Music expresses that which cannot be put into words and that which cannot remain silent.
--Victor Hugo
------------------------------------------------------------------------------------------

Cool site of the moment:http://www.zod2008.com/
  Send a message via MSN to mojo-ris-in Send a message via Yahoo to mojo-ris-in  
Reply With Quote
  (#4) Old
Jeramey Offline
Zeropaid Regular
Jeramey Reputation is 0
 
Jeramey's Avatar
 
Posts: 10
Join Date: Apr 2002
Reputation Power: 0
Talking September 12th, 2002, 07:17 AM

Thank you for spreading the word about the fix without having to use SP1.

  Send a message via AIM to Jeramey  
Reply With Quote
  (#5) Old
Foreverboard Offline
Alien in Penguin suit....
Foreverboard Reputation is 0
 
Foreverboard's Avatar
 
Posts: 859
Join Date: Apr 2002
Location: somewhere....
Age: 31
Reputation Power: 135
September 12th, 2002, 07:27 AM

I found this out yesterday and tested it, crazy how it works.


foreverboard
(theonlybob)

"There's gonna be some stuff u gonna see that's gonna make it hard To smile in the future, but through whatever you see, Through all the rain and all the pain, you gotta keep your sense of humor. you gotta be able to smile through all this bullshit"
-Tupac Shakur


www.theonlybob.com

Do YOU Streamload?????? www.Streamload.com
   
Reply With Quote
  (#6) Old
Carpe Diem Offline
Zeropaid Regular
Carpe Diem Reputation is 0
 
Carpe Diem's Avatar
 
Posts: 19
Join Date: Jul 2002
Location: SEIZE THE DAY
Reputation Power: 0
September 12th, 2002, 07:44 AM

hey richard, nice read, catch ya around. rtw


SEIZE THE DAY
   
Reply With Quote
  (#7) Old
PorkSwordsman Offline
Zeropaid Regular
PorkSwordsman Reputation is 0
 
PorkSwordsman's Avatar
 
Posts: 55
Join Date: Jul 2002
Age: 39
Reputation Power: 93
Talking the answer - September 12th, 2002, 09:56 AM

http://www.bigfix.com/


Go to the above address and download the free bigfix client, i have used it for years and it automatically scans windows for any security issues and downloads the relevant patches for your software - works on any version of windows, you will be surprised what it picks up!! when doing a new install after i have got windows running i automatically patch it with bigfix - tip - if like me and the other sensible people you have a hacked pirate version of xp ( i have a triboot setup) p.s. i have never paid for windows ever!!!! DONT download Servicepack 1 as it will take out the non expiry patch and disable XP all the other patches are ok.:cross
   
Reply With Quote
  (#8) Old
Rickio Offline
Zeropaid Regular
Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500Rickio Reputation is 1500
 
Rickio's Avatar
 
Posts: 1,941
Join Date: Apr 2002
Location: So Cal
Reputation Power: 205
xp-antispy - September 12th, 2002, 06:38 PM

here is a little app that disables xp's autoupates and more if you don't trust micro$oft.

http://xp-antispy.de/index.html?/news-e.htm

I went to the website and it was down, so I just posted the file in case anyone is interested.

btw, if you will be updating to sp1, don't install this till after you update or sp1 will not update.

sharereactor has winXPproCorp with sp1integrated if anyone wants to jump on that.

Attached Files
File Type: zip xpantispy3-english.zip (26.6 KB, 17 views)

Last edited by Rickio; September 12th, 2002 at 06:43 PM.
  Send a message via AIM to Rickio  
Reply With Quote
  (#9) Old
jonny5 Offline
Mr Roboto
jonny5 Reputation is 0
 
jonny5's Avatar
 
Posts: 293
Join Date: Sep 2002
Location: irc.p2pchat.net
Reputation Power: 102
September 12th, 2002, 08:44 PM

I updated to sp1 so I guess i'm safe from this hack. *shakes head at microsoft*
Now I just wish gta3 would work w/ sp1 :/


Join P2pChat
fhqwhgads
   
Reply With Quote
  (#10) Old
hawkburn Offline
Yup...
hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500hawkburn Reputation is 1500
 
hawkburn's Avatar
 
Posts: 2,316
Join Date: Jun 2002
Age: 22
Reputation Power: 224
September 15th, 2002, 11:29 AM

i consider myself safe ---so far--- with SP1


My current setup stats (like anyone cares...):

ASUS A8N32-SLI Motherboard
AMD 4400+ Dual-Core CPU
Windows Vista (Ultimate 32bit)
2 GB (2x1GB) Corsair XMS RAM
2x250 GB (in RAID 0) HDDs
EVGA GeForce 7950 GTX 512 MB
Creative X-FI Fatal1ty XtremeGamer

Also sporting a black MacBook
Revision/Release 1
Upgraded to 2GB RAM.
  Send a message via AIM to hawkburn Send a message via MSN to hawkburn  
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off




vBulletin Skin developed by: vBStyles.com