<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>thebackroomtech &#187; Vulnerability</title>
	<atom:link href="http://thebackroomtech.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://thebackroomtech.com</link>
	<description>serving up the info back room techs everywhere find interesting</description>
	<lastBuildDate>Sat, 20 Nov 2010 03:13:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Direct patch download links for MS10-002 KB978207</title>
		<link>http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/</link>
		<comments>http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 16:56:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[978207]]></category>
		<category><![CDATA[CVE-2010-0249]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[KB978207]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MS10-002]]></category>
		<category><![CDATA[out of band]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://thebackroomtech.com/?p=2084</guid>
		<description><![CDATA[Microsoft had released the out of band patch to resolve Internet Explorer vulnerabilities, see KB978207 and MS10-002 for additional details. The patches for IE6, IE7, and IE8 are available on Windows Update and Microsoft Update.  Unfortunately for me, our business proxy blocks access to these sites.  We also have to go through a corporate vulnerability rating process, [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Microsoft had released the out of band patch to resolve Internet Explorer vulnerabilities, see <a href="http://support.microsoft.com/kb/978207" target="_blank">KB978207</a> and <a href="http://www.microsoft.com/technet/security/bulletin/MS10-002.mspx" target="_blank">MS10-002</a> for additional details.</p>
<p>The patches for IE6, IE7, and IE8 are available on Windows Update and Microsoft Update.  Unfortunately for me, our business proxy blocks access to these sites.  We also have to go through a corporate vulnerability rating process, and if the vulnerability rates severe enough, a deployment plan will be developed, and tested, and scheduled&#8230;. long story short, without intervention on my part, it will be a long time until my machine sees any critical updates.</p>
<p>The ISC has <a href="http://isc.sans.org/diary.html?n&amp;storyid=8062" target="_blank">rated this vulnerability</a> at it&#8217;s highest risk level, PATCH NOW!</p>
<p>I manually downloaded the patch from the Microsoft download site.  You can find the patch for all OSs and versions of IE <a href="http://www.microsoft.com/downloads/en/results.aspx?freetext=security+update+ms10-002&amp;displaylang=en&amp;stype=s_basic" target="_blank">here</a>.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/" title="MS08-067 vulnerability, exploit, and reverse engineering in detail">MS08-067 vulnerability, exploit, and reverse engineering in detail</a></li><li><a href="http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/" title="New Internet Explorer 7 0-day exploit">New Internet Explorer 7 0-day exploit</a></li><li><a href="http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/" title="Out of the Box, the ASUS Eee PC is Incredibly Insecure">Out of the Box, the ASUS Eee PC is Incredibly Insecure</a></li><li><a href="http://thebackroomtech.com/2009/07/14/vista-x86-patch-to-address-4gb-of-ram/" title="Vista x86 patch to address 4GB+ of RAM">Vista x86 patch to address 4GB+ of RAM</a></li><li><a href="http://thebackroomtech.com/2009/02/25/free-microsoft-ebook-windows-vista-resource-kit-second-edition/" title="Free Microsoft eBook: Windows Vista Resource Kit, Second Edition">Free Microsoft eBook: Windows Vista Resource Kit, Second Edition</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Internet Explorer 7 0-day exploit</title>
		<link>http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/</link>
		<comments>http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/#comments</comments>
		<pubDate>Wed, 10 Dec 2008 09:42:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[zero day]]></category>

		<guid isPermaLink="false">http://thebackroomtech.com/?p=1248</guid>
		<description><![CDATA[SANS has reported a Microsoft IE7 0-day expoit that is now in the wild. This vulnerability is not adderssed by the forthcoming December 2008 patch Tuesday releases, or by the MS08-073 patch that was released on 12-09-2008. Analysis shows the current exploit checks for the following conditions: The user has to be running Internet Explorer [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://isc.sans.org/diary.html?storyid=5458">SANS has reported</a> a Microsoft IE7 0-day expoit that is now in the wild.  This vulnerability is not adderssed by the forthcoming December 2008 patch Tuesday releases, or by the MS08-073 patch that was released on 12-09-2008.</p>
<p>Analysis shows the current exploit checks for the following conditions:</p>
<p>The user has to be running Internet Explorer<br />
The version of Internet Explorer has to be 7<br />
The operating system has to be Windows XP or Windows 2003</p>
<p>SANS has not yet confirmed if other versions are affected (Internet Explorer 6 or Internet Explorer 7 on Microsoft Windows Vista).</p>
<p>ThreatExpert has a <a href="http://www.threatexpert.com/report.aspx?md5=A4F025331518F4AE96915FC55A4F2D38">very nice overview</a> of the modifications the exploit makes to compromised computers.</p>
<p>Additional Resources:</p>
<p><a href="http://blogs.zdnet.com/security/?p=2283#more-2283">ZDNet Security Blog</a><br />
<a href="http://secunia.com/Advisories/33089/">Secunia Advisory</a></p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/" title="Direct patch download links for MS10-002 KB978207">Direct patch download links for MS10-002 KB978207</a></li><li><a href="http://thebackroomtech.com/2009/01/28/howto-disable-the-internet-explorer-popup-this-page-contains-both-secure-and-non-secure-items-do-you-want-to-display-the-nonsecure-items/" title="Howto disable the Internet Explorer popup: This page contains both secure and non-secure items. Do you want to display the nonsecure items?">Howto disable the Internet Explorer popup: This page contains both secure and non-secure items. Do you want to display the nonsecure items?</a></li><li><a href="http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/" title="MS08-067 vulnerability, exploit, and reverse engineering in detail">MS08-067 vulnerability, exploit, and reverse engineering in detail</a></li><li><a href="http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/" title="Out of the Box, the ASUS Eee PC is Incredibly Insecure">Out of the Box, the ASUS Eee PC is Incredibly Insecure</a></li><li><a href="http://thebackroomtech.com/2008/01/28/cannot-uninstall-ie7-from-windows-server-2003/" title="Cannot Uninstall IE7 from Windows Server 2003">Cannot Uninstall IE7 from Windows Server 2003</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS08-067 vulnerability, exploit, and reverse engineering in detail</title>
		<link>http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/</link>
		<comments>http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 08:37:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[958644]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Exploit:Win32/MS08067.gen!A]]></category>
		<category><![CDATA[Gimmiv]]></category>
		<category><![CDATA[Gimmiv.A]]></category>
		<category><![CDATA[kb 958644]]></category>
		<category><![CDATA[kb958644]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MS08-067]]></category>
		<category><![CDATA[out of band]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://thebackroomtech.wordpress.com/?p=1100</guid>
		<description><![CDATA[Since Microsoft released the out of band patch detailed in MS08-067 yesterday, an exploit and worm have already been developed and seen in the wild.  Dave Aitel announced the exploit yesterday in his DailyDave mailing list. SecurityFocus has the exploit available for download here.  Alexander has also published his decompiled version of the vulnerable function.  Stephenl [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Since Microsoft released the out of band patch detailed in <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">MS08-067</a> yesterday, an exploit and worm have already been developed and seen in the wild.  <a href="http://seclists.org/dailydave/2008/q4/0034.html" target="_blank">Dave Aitel announced the exploit</a> yesterday in his DailyDave mailing list. SecurityFocus has <a href="http://www.securityfocus.com/data/vulnerabilities/exploits/31874.zip" target="_blank">the exploit available for download here</a>.  <a href="http://www.phreedom.org/blog/2008/decompiling-ms08-067/" target="_blank">Alexander has also published</a> his decompiled version of the vulnerable function.  <a href="http://www.dontstuffbeansupyournose.com/?p=35" target="_blank">Stephenl has a nice description</a> of how he reverse engineered the patches to determine the specific vulnerability.</p>
<p>The <a href="http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html" target="_blank">ThreatExpert Blog</a> has a very nice description of how the worm, named Gimmiv.A operates. Gimmiv.A creates three files in the %system%\WBEM\ directory: winbase.dll, basesvc.dll, and syicon.dll.</p>
<p>ThreatExpert reports</p>
<p>&#8220;After dropping and loading the aforementioned DLLs, the worm will collect system information from the compromised computer, collect passwords from the Windows protected storage and Outlook Express passwords cache, and post collected details to a remote host. The details are posted in an encrypted form, by using AES (Rijndael) encryption. </p>
<p>Details collected by Gimmiv.A are then posted to a personal profile of the user &#8220;perlbody&#8221;, hosted with http://www.t35.com hosting provider. At the time of this writing, there are 3,695 entries in that file. Every line contains an encrypted string, which could potentially conceal current victims&#8217; details, indirectly indicating how many victims have been compromised by this worm so far.</p>
<p>The most interesting part of this worm is implemented in the DLL basesvc.dll. This DLL is responsible for the network propagation of the worm.&#8221;</p>
<p>If you cannot immediately patch your systems, the best defense is to restrict access to ports 139 and 445.</p>
<p>For additional detail, see <a href="http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx" target="_blank">this Microsoft Security Vulnerability Research &amp; Defense blog posting</a>.</p>
<p>The <a href="http://www.microsoft.com/security/portal/Entry.aspx?name=TrojanSpy%3aWin32%2fGimmiv.A" target="_blank">Microsoft Malware Protection Center has a page dedicated to Gimmiv.A</a>, which they are calling a trojan rather than a worm.</p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2008/10/24/first-glimpse-into-ms08-067-exploits-in-the-wild/" target="_blank">McAfee has a nice description</a> of the exploit code as well.</p>
<p>You can <a href="http://www.virustotal.com/analisis/44ab3e26f3942dce07f4df341ab3515a" target="_blank">verify your anti-virus vendor detects Gimmiv.A</a> at virustotal.com</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/" title="Direct patch download links for MS10-002 KB978207">Direct patch download links for MS10-002 KB978207</a></li><li><a href="http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/" title="New Internet Explorer 7 0-day exploit">New Internet Explorer 7 0-day exploit</a></li><li><a href="http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/" title="Out of the Box, the ASUS Eee PC is Incredibly Insecure">Out of the Box, the ASUS Eee PC is Incredibly Insecure</a></li><li><a href="http://thebackroomtech.com/2009/07/14/vista-x86-patch-to-address-4gb-of-ram/" title="Vista x86 patch to address 4GB+ of RAM">Vista x86 patch to address 4GB+ of RAM</a></li><li><a href="http://thebackroomtech.com/2009/02/25/free-microsoft-ebook-windows-vista-resource-kit-second-edition/" title="Free Microsoft eBook: Windows Vista Resource Kit, Second Edition">Free Microsoft eBook: Windows Vista Resource Kit, Second Edition</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sun Java Multiple Security Vulnerabilities Rated Highly Critical</title>
		<link>http://thebackroomtech.com/2008/07/10/sun-java-multiple-security-vulnerabilities-rated-highly-critical/</link>
		<comments>http://thebackroomtech.com/2008/07/10/sun-java-multiple-security-vulnerabilities-rated-highly-critical/#comments</comments>
		<pubDate>Thu, 10 Jul 2008 06:57:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://thebackroomtech.wordpress.com/?p=379</guid>
		<description><![CDATA[Sun has disclosed multiple security vulnerabilities within their Java product, which are summarized here.  The categories of vulnerabilities include: 1) Security Bypass 2) Exposure of system information 3) Exposure of sensitive information 4) DoS 5) System access The following Sun products are affected: Java Web Start 1.x Java Web Start 5.x Java Web Start 6.x [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Sun has disclosed multiple security vulnerabilities within their Java product, which are <a href="http://secunia.com/advisories/31010/" target="_blank">summarized here</a>.  The categories of vulnerabilities include:</p>
<p>1) Security Bypass<br />
2) Exposure of system information<br />
3) Exposure of sensitive information<br />
4) DoS<br />
5) System access</p>
<p>The following Sun products are affected:</p>
<p>Java Web Start 1.x<br />
Java Web Start 5.x<br />
Java Web Start 6.x<br />
Sun Java JDK 1.5.x<br />
Sun Java JDK 1.6.x<br />
Sun Java JRE 1.3.x<br />
Sun Java JRE 1.4.x<br />
Sun Java JRE 1.5.x / 5.x<br />
Sun Java JRE 1.6.x / 6.x<br />
Sun Java SDK 1.3.x<br />
Sun Java SDK 1.4.x</p>
<p>The recommendation is to update your software immediately to a patched version:</p>
<p>JDK and JRE 6 Update 7:<br />
<a href="http://java.sun.com/javase/downloads/index.jsp" target="_blank">http://java.sun.com/javase/downloads/index.jsp</a></p>
<p>JDK and JRE 5.0 Update 16:<br />
<a href="http://java.sun.com/javase/downloads/index_jdk5.jsp" target="_blank">http://java.sun.com/javase/downloads/index_jdk5.jsp</a></p>
<p>SDK and JRE 1.4.2_18:<br />
<a href="http://java.sun.com/j2se/1.4.2/download.html" target="_blank">http://java.sun.com/j2se/1.4.2/download.html</a></p>
<p>SDK and JRE 1.3.1_23 (for customers with Solaris 8 and Vintage Support Offering support contracts):<br />
<a href="http://java.sun.com/j2se/1.3/download.html" target="_blank">http://java.sun.com/j2se/1.3/download.html</a></p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2008/02/25/vmware-running-on-windows-host-security-hole/" title="VMware Running on Windows Host Security Hole">VMware Running on Windows Host Security Hole</a></li><li><a href="http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/" title="Out of the Box, the ASUS Eee PC is Incredibly Insecure">Out of the Box, the ASUS Eee PC is Incredibly Insecure</a></li><li><a href="http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/" title="Direct patch download links for MS10-002 KB978207">Direct patch download links for MS10-002 KB978207</a></li><li><a href="http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/" title="New Internet Explorer 7 0-day exploit">New Internet Explorer 7 0-day exploit</a></li><li><a href="http://thebackroomtech.com/2008/12/08/windows-installer-cleanup-utility/" title="Windows Installer CleanUp Utility">Windows Installer CleanUp Utility</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2008/07/10/sun-java-multiple-security-vulnerabilities-rated-highly-critical/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware Running on Windows Host Security Hole</title>
		<link>http://thebackroomtech.com/2008/02/25/vmware-running-on-windows-host-security-hole/</link>
		<comments>http://thebackroomtech.com/2008/02/25/vmware-running-on-windows-host-security-hole/#comments</comments>
		<pubDate>Mon, 25 Feb 2008 09:07:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://thebackroomtech.wordpress.com/?p=271</guid>
		<description><![CDATA[If you are running VMware on a Windows host configured with host-to-guest shared folders, it is possible for a program running in the guest to gain access to the host&#8217;s complete file system and create or modify executable files in sensitive locations. A vulnerability exists in VMware&#8217;s shared folders mechanism that grants users of a [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>If you are running VMware on a Windows host configured with host-to-guest shared folders,  <a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=1004034" target="_blank">it is possible for a program running in the guest to gain access to the host&#8217;s  complete file system</a> and create or modify executable files in sensitive  locations.</p>
<p>A vulnerability exists in VMware&#8217;s shared folders mechanism that grants users  of a Guest system read and write access to any portion of the Host&#8217;s file system  including the system folder and other security-sensitive files. Exploitation of  this vulnerability allows attackers to break out of an isolated Guest system to  compromise the underlying Host system that controls it.</p>
<p>Affected versions include:</p>
<ul>
<li>
<div>VMware Workstation 6.0.2 and earlier</div>
</li>
<li>
<div>VMware Workstation 5.5.4 and earlier</div>
</li>
<li>
<div>VMware Player 2.0.2 and earlier</div>
</li>
<li>
<div>VMware Player 1.0.4 and earlier</div>
</li>
<li>
<div>VMware ACE 2.0.2 and earlier</div>
</li>
<li>VMware ACE 1.0.2 and earlier</li>
</ul>
<div><b></b>The following VMware products are not affected:</div>
<ul>
<li>
<div>VMware Server is not affected because it does not use shared folders.</div>
</li>
<li>
<div>No versions of ESX Server, including ESX Server 3i, are affected by this  vulnerability. Because ESX Server is based on a bare-metal hypervisor  architecture, not a hosted architecture, it does not include any shared folder  abilities.</div>
</li>
<li>
<div>VMware Fusion and Linux-hosted VMware products are  unaffected.</div>
</li>
</ul>
<h3>Workaround</h3>
<div>Until VMware releases a patch to fix this issue, users of affected  Windows-hosted VMware products should disable shared folders.<b>To  disable shared folders in the Global settings:</b></div>
<ol>
<li>
<div>From the VMware product&#8217;s menu, choose <b>Edit</b> &gt;  <b>Preferences</b>.</div>
</li>
<li>
<div>In the <b>Workspace</b> tab, under <b>Virtual  Machines</b>, deselect the checkbox for <b>Enable all shared folders  by default</b>.</div>
</li>
</ol>
<div><b>To disable shared folders for the individual virtual machine  settings:</b></div>
<ol>
<li>
<div>From the VMware product&#8217;s menu, choose <b>VM</b> &gt;  <b>Settings</b>.</div>
</li>
<li>
<div>In the <b>Options</b> tab, select <b>Shared Folders</b>  and <b>Disable</b>.</div>
</li>
</ol>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2008/07/18/free-configcheck-utility-for-vmware-esx-host-security-assesment/" title="Free ConfigCheck Utility for VMware ESX host security assesment">Free ConfigCheck Utility for VMware ESX host security assesment</a></li><li><a href="http://thebackroomtech.com/2008/07/10/sun-java-multiple-security-vulnerabilities-rated-highly-critical/" title="Sun Java Multiple Security Vulnerabilities Rated Highly Critical">Sun Java Multiple Security Vulnerabilities Rated Highly Critical</a></li><li><a href="http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/" title="Out of the Box, the ASUS Eee PC is Incredibly Insecure">Out of the Box, the ASUS Eee PC is Incredibly Insecure</a></li><li><a href="http://thebackroomtech.com/2010/07/08/vmware-converter-p2v-fails-with-fatal-error/" title="VMware Converter P2V Fails with Fatal Error">VMware Converter P2V Fails with Fatal Error</a></li><li><a href="http://thebackroomtech.com/2010/06/28/fix-incompatible-device-specified-for-device-0-when-cold-migrating-vmware-guest/" title="Fix: Incompatible device specified for device &#8217;0&#8242; when cold migrating VMware guest">Fix: Incompatible device specified for device &#8217;0&#8242; when cold migrating VMware guest</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2008/02/25/vmware-running-on-windows-host-security-hole/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Out of the Box, the ASUS Eee PC is Incredibly Insecure</title>
		<link>http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/</link>
		<comments>http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 09:13:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[ASUS]]></category>
		<category><![CDATA[Eee PC]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://thebackroomtech.wordpress.com/?p=268</guid>
		<description><![CDATA[HDM pointed out on the Metasploit blog that the guys from RISE Security rooted an ASUS Eee PC quite easily. They used Metasploit to exploit a Samba vulnerability that was published in July 2007 &#8211; almost seven months ago. Why is ASUS shipping new products with vulnerabilities that are serious enough to allow attackers to [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>HDM <a href="http://blog.metasploit.com/2008/02/rise-security-vs-asus-eee-pc.html" target="_blank">pointed out</a> on the <a href="http://blog.metasploit.com" target="_blank">Metasploit blog</a> that the guys from RISE Security <a href="http://www.risesecurity.org/blog/entry/6/" target="_blank">rooted an ASUS Eee PC</a> quite easily.  They used Metasploit to <a href="http://www.risesecurity.org/exploit/5/" target="_blank">exploit a Samba vulnerability</a> that was published in July 2007 &#8211; almost seven months ago.</p>
<p>Why is ASUS shipping new products with vulnerabilities that are serious enough to allow attackers to gain root access through commonly used security tools such as the <a href="http://www.metasploit.com/projects/Framework/" target="_blank">Metasploit Framework</a>?</p>
<p><a href="http://candyfoss.com/2008/02/11/eee-pc-hacked-out-of-the-box-pfft/" target="_blank">Carl at CandyFOSS</a> doesn&#8217;t think this could realistically be exploited, but I&#8217;m not so sure.</p>
<p>I&#8217;ve searched all over ASUS&#8217;s support website, and have not found a downloadable patch for this problem.  One of my school districts just ordered 60 Eee PCs , and you can rest assured there&#8217;s no way I&#8217;m letting these devices out of the box until I can find a fix.</p>
<p>Anyone out there who has one of these machines, can you confirm if there is a patch that is automatically installed through the update process to address this vulnerability?</p>
<p>The <a href="http://isc.sans.org" target="_blank">ISC</a> has a <a href="http://isc.sans.org/diary.html?storyid=3687&amp;rss" target="_blank">brief write-up</a> of additional information the Eee PC reveals in it&#8217;s default configuration.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/" title="Direct patch download links for MS10-002 KB978207">Direct patch download links for MS10-002 KB978207</a></li><li><a href="http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/" title="New Internet Explorer 7 0-day exploit">New Internet Explorer 7 0-day exploit</a></li><li><a href="http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/" title="MS08-067 vulnerability, exploit, and reverse engineering in detail">MS08-067 vulnerability, exploit, and reverse engineering in detail</a></li><li><a href="http://thebackroomtech.com/2008/07/10/sun-java-multiple-security-vulnerabilities-rated-highly-critical/" title="Sun Java Multiple Security Vulnerabilities Rated Highly Critical">Sun Java Multiple Security Vulnerabilities Rated Highly Critical</a></li><li><a href="http://thebackroomtech.com/2008/02/25/vmware-running-on-windows-host-security-hole/" title="VMware Running on Windows Host Security Hole">VMware Running on Windows Host Security Hole</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2008/02/21/out-of-the-box-the-asus-eee-pc-is-incredibly-insecure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major Websense Content Filter Bypass Vulnerability</title>
		<link>http://thebackroomtech.com/2008/01/11/major-websense-content-filter-bypass-vulnerability/</link>
		<comments>http://thebackroomtech.com/2008/01/11/major-websense-content-filter-bypass-vulnerability/#comments</comments>
		<pubDate>Fri, 11 Jan 2008 08:03:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[firefox]]></category>
		<category><![CDATA[Content Filter]]></category>
		<category><![CDATA[ISA Server 2004]]></category>
		<category><![CDATA[MSN Messenger]]></category>
		<category><![CDATA[RealPlayer]]></category>
		<category><![CDATA[User Agent]]></category>
		<category><![CDATA[User Agent Switcher]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[WebEx]]></category>
		<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://thebackroomtech.wordpress.com/2008/01/11/major-websense-content-filter-bypass-vulnerability/</guid>
		<description><![CDATA[I almost missed this Websense vulnerability, since it was published 12-21-2007, while I was on vacation. I&#8217;ve verified it works on one of my client&#8217;s networks using Firefox Portable 2.0.0.4, Websense 6.1.1, ISA Server 2004 Standard, and User Agent Switcher 0.6.10. Mr HinkyDink, who discovered the issue used Websense 6.3.1, so I&#8217;m sure other Websense [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>I almost missed <a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6511" target="_blank">this Websense vulnerability</a>, since it was published 12-21-2007, while I was on vacation.  I&#8217;ve verified it works on one of my client&#8217;s networks using Firefox Portable 2.0.0.4, Websense 6.1.1, ISA Server 2004 Standard, and <a href="https://addons.mozilla.org/en-US/firefox/addon/59" target="_blank">User Agent Switcher 0.6.10</a>.</p>
<p><a href="http://mrhinkydink.blogspot.com" target="_blank">Mr HinkyDink</a>, who <a href="http://mrhinkydink.blogspot.com/2007/12/websense-policy-filtering-bypass.html" target="_blank">discovered the issue</a> used Websense 6.3.1, so I&#8217;m sure other Websense versions are susceptible as well.  His instructions are:</p>
<p>I.  Install FireFox 2.0.x</p>
<p>II. Obtain and install the User Agent Switcher browser plug-in  by Chris Pederick</p>
<p>III. Add the following User Agents to the plug-in</p>
<p>Description: RealPlayer<br />
User Agent : RealPlayer G2</p>
<p>Description: MSN Messenger<br />
User Agent : MSMSGS</p>
<p>Description: WebEx<br />
User Agent : StoneHttpAgent</p>
<p>IV.  Change FireFox&#8217;s User Agent to any one of the preceding values</p>
<p>V.   Browse to a filtered Web site</p>
<p>VI.  Content is allowed</p>
<p>Content browsed via this method will be recorded in the Websense database as being in the &#8220;Non-HTTP&#8221; category.</p>
<p>See also Websense KnowledgeBase article #976, Websense cleaned up this issue in database #92938.</p>
<p>I work with a ton of school districts, all who are required by law to provide content filtering.  We constantly struggle to keep ahead of the various methods of bypassing the filter that students find, but I really don&#8217;t fault the kids for being curious, or trying to outsmart the adults.  I think the fault lies with the teachers who are supposed to be supervising, but instead allow the students to do whatever they want.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://thebackroomtech.com/2010/01/21/direct-patch-download-links-for-ms10-002-kb978207/" title="Direct patch download links for MS10-002 KB978207">Direct patch download links for MS10-002 KB978207</a></li><li><a href="http://thebackroomtech.com/2008/12/10/new-internet-explorer-7-0-day-exploit/" title="New Internet Explorer 7 0-day exploit">New Internet Explorer 7 0-day exploit</a></li><li><a href="http://thebackroomtech.com/2008/10/24/ms08-067-exploit-and-worm-in-the-wild-already/" title="MS08-067 vulnerability, exploit, and reverse engineering in detail">MS08-067 vulnerability, exploit, and reverse engineering in detail</a></li><li><a href="http://thebackroomtech.com/2008/08/27/registering-firefox-portable-as-the-default-windows-browser/" title="Howto: Register Firefox Portable as the default Windows browser">Howto: Register Firefox Portable as the default Windows browser</a></li><li><a href="http://thebackroomtech.com/2008/08/26/cmu-announces-free-firefox-add-on-to-increase-browser-security-against-dns-flaw-and-digital-signature-problems/" title="CMU announces free Firefox add-on to increase browser security against DNS flaw and digital signature problems">CMU announces free Firefox add-on to increase browser security against DNS flaw and digital signature problems</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://thebackroomtech.com/2008/01/11/major-websense-content-filter-bypass-vulnerability/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 32/57 queries in 0.021 seconds using disk: basic
Object Caching 1015/1036 objects using disk: basic

Served from: thebackroomtech.com @ 2012-05-22 22:47:30 -->
