Oct 2 2003

EarthStation 5 P2P application contains malicious code

  • Written by random nut
  • No Comments

ES5 info

EarthStation 5 (aka ES5, aka ESV) (http://www.earthstation5.com and http://forums2.es5.com/) is a P2P application first released about 6-12 months ago. The people behind ES5 claim that ES5 is the most secure P2P software in the world. They also claim that they are security experts, and that they have more than 15 million simultaneous users on-line 24/7. In comparison Kazaa, the most popular P2P application, only has about 4 million simultaneous users on-line at any given time of day.


Malicious code

There exists malicious code in ES5.exe’s “Search Service” packet handler. By sending packet 0Ch, sub-function 07h to the “Search Service”’s IP:Port, a remote attacker could delete any file the user is sharing. If the remote attacker uses “filenames” with a relative path in them (eg. “……WINDOWSNOTEPAD.EXE”), the remote attacker could also delete files in eg. the windows and windowssystem32 folders, or any other folder on the same partition as any of the shared folders. Since most users using Windows are in the Administrators group, a remote attacker could also delete the C:BOOT.INI file which is a required boot file used by ntldr.


IMPORTANT: This is not a bug! They intentionally added this code to ES5.


Vulnerabilities

There also exists a lot of other vulnerabilities in ES5 (eg. DoS attacks, buffer overflow bugs, and so on), but these all seem to be unintentional. Another advisory may have more info on these vulnerabilities, but I’m not their beta tester so don’t hold your breath.


Conclusion

The people behind ES5 have intentionally added malicious code to ES5. If you have followed the ES5 discussions on message boards and read what the ES5 people have said and done (eg. DoS attacking BitTorrent sites), this comes as no surprise. The question then is “why did they do it?” I’m sure they won’t tell us, but here’s a theory: They could be working for the RIAA, MPAA, or a similar organization. Once they have enough users on their ES5 network, they would start deleting all copyrighted files they own which their users are sharing. The users wouldn’t know what hit them.


Tested ES5 builds

ES5 build 1266


ES5 build 2180 (latest version)


MD5 sums of files

MD5 sum (using RFC 1321 source code) of tested files (just in case the ES5 people will remove the malicious code w/o changing the build number)


e35838ef6668abe883344e3a7e734794 *es5beta1266.exe
ce44a1f0542b9132f2debd9866febc65 *es5beta2180.exe
373c30ba0e8b1dce05dcab2acce94a77 *es5_build1266.exe
915de0f8e72be40bf071a86bc9dc2626 *es5_build2180.exe


2,244,663 es5_build1266.exe (ES5.exe – build 1266)
2,347,063 es5_build2180.exe (ES5.exe – build 2180 – latest version)
4,436,309 es5beta1266.exe (ES5 installer – build 1266)
4,553,325 es5beta2180.exe (ES5 installer – build 2180 – latest version)


The official ES5 installer download URL is http://download.es5.com/es5beta.exe , but check its MD5 sum before installing it in case they changed it.


Credits

me :) for discovering it (randnut@yahoo.com)


Exploit code

Go to http://www.geocities.com/esvuln to download the exploit binary if you don’t want to compile it yourself.


Source code to esv (”ExpoitStation 5″ or “EarthStation Vulnerabilities”, you decide) but first a little FAQ…


Uninstall Instructions



  1. Kill all ES5.exe processes with task manager (taskmgr.exe)
  2. Try ES5’s uninstaller
  3. Delete registry key HKEY_CURRENT_USERSoftwareHelmuthSpeakingForBosko ne
  4. Delete registry key HKEY_LOCAL_MACHINESOFTWAREEarthStation5
  5. Remove the ES5 entry from HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurre ntVersionRun to stop it from running after reboot
  6. Remove the ES5 entry from HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurr entVersionRun to stop it from running after reboot
  7. Delete all files in the ES5 folder (usually in “C:Program FilesEarthStation5″). If files can’t be deleted, boot into safe mode and delete them.
  8. Restart computer

The rest can be found here

Related Posts

  1. Malicious code could trick ZoneAlarm firewall
  2. RealNetworks Warns of Media Player Flaws
  3. Kazaa security hole undermines network
  4. Kazaa Security Flaw
  5. Apple fixes critical iTunes bug
Zeropaid on Facebook
Trackbacks url:

Leave a Comment...

  • Advertisement

    Giganews Newsgroups

1 Star2 Stars3 Stars4 Stars5 Stars Loading ... Loading ...

  • Smartass: Jag tror inte att någon kommer in just nu......
  • Ron: Do you know of a site where I can down load several days of music as it wouold be played in a night club. An auto D.J. f...
  • Buzz: I loved Demonoid but, there still down and would like to try iptorrent.com. Could I get a invite? Did you ever get back...
  • Sophieanne and Lilli: I wish their was more music....
  • ralphie: OH looky, it still doesn't work on dual screens. Adobe sucks....
  • odball: hej jag är en leged user och nu kommer jag inte in på sidan kan ni vara snälla och undersöka varför mvh G.P...
  • mpsharp.com Blog » Watching NFL games online: [...] show you a number of streams to choose from for each game.  All the streams require some sort of StreamTorrent pl...
  • ejonesss: no it is not going to completely stop piracy because while it will stop those whose reason for piracy is quality it is n...
  • sdsd