Showing posts with label micrsoft. Show all posts
Showing posts with label micrsoft. Show all posts

Saturday, January 30, 2010

Microsoft, Aurora and something about forest and trees?

Perhaps it is the fine tequila this evening, but I really don't get how our industry can latch on to the recent 'Aurora' incident and try to take Microsoft to task about it. The amount of news on this has been overwhelming, and I will try to very roughly summarize:

News surfaces Google, Adobe and 30+ companies hit by "0-day" attack

Google uses this for political overtones

Originally thought to be Adobe 0-day, revealed it was MSIE 0-day

Jan 14, confirmed it is MSIE vuln, shortly after dubbed "aurora"

Jan 21, uproar over MS knowing about the vuln since Sept

Now, here is where we get to the whole forest, trees and some analogy about eyesight. Oh, I'll warn (and surprise) you in advance, I am giving Microsoft the benefit of the doubt here (well, for half the blog post) and throwing this back at journalists and the security community instead. Let's look at this from a different angle.

The big issue that is newsworthy is that Microsoft knew of this vulnerability in September, and didn't issue a patch until late January. What is not clear, is if Microsoft knew it was being exploited. The wording of the Wired article doesn't make it clear: "aware months ago of a critical security vulnerability well before hackers exploited it to breach Google, Adobe and other large U.S. companies" and "Microsoft confirmed it learned of the so-called 'zero-day' flaw months ago". Errr, nice wording. Microsoft was aware of the vulnerability (technically), before hackers exploited it, but doesn't specifically say if they KNEW hackers were exploiting it. Microsoft learned of the "0-day" months ago? No, bad bad bad. This is taking an over-abused term and making it even worse. If a vulnerability is found and reported to the vendor before it is exploited, is it still 0-day (tree, forest, no one there to hear it falling)?

Short of Microsoft admitting they knew it was being exploited, we can only speculate. So, for fun, let's give them a pass on that one and assume it was like any other privately disclosed bug. They were working it like any other issue, fixing, patching, regression testing, etc. Good Microsoft!

Bad Microsoft! But, before you jump on the bandwagon, bad journalists! Bad security community!

Why do you care they sat on this one vulnerability for six months? Why is that such a big deal? Am I the only one who missed the articles pointing out that they actually sat on five code execution bugs for longer? Where was the outpour of blogs or news articles mentioning that "aurora" was one of six vulnerabilities reported to them during or before September, all in MSIE, all that allowed remote code execution (tree, forest, not seeing one for the other)?
CVE Reported to MS Disclosed Time to Patch
CVE-2010-0244 2009-07-14 2010-01-21 6 Months, 7 Days (191 days)
CVE-2010-0245 2009-07-14 2010-01-21 6 Months, 7 Days (191 days)
CVE-2010-0246 2009-07-16 2010-01-21 6 Months, 5 Days (189 days)
CVE-2010-0248 2009-08-14 2010-01-21 5 Months, 7 days (160 days)
CVE-2010-0247 2009-09-03 2010-01-21 4 Months, 18 days (140 days)
CVE-2010-0249 2009-09-?? 2010-01-14 4 Months, 11 days (133 days) - approx
CVE-2010-0027 2009-11-15 2010-01-21 2 Months, 6 days (67 days)
CVE-2009-4074 2009-11-20 2009-11-21 2 Months, 1 day (62 days)

Remind me again, why the "Aurora" conspiracy is noteworthy? If Microsoft knew of six remote code execution bugs, all from the September time-frame, why is one any more severe than the other? Is it because one was used to compromise hosts, detected and published in an extremely abnormal fashion? Are we actually trying to hold Microsoft accountable on that single vulnerability when the five others just happened not to be used to compromise Google, Adobe and others?

Going back to the Wired article, they say on the second to last paragraph: "On Thursday, meanwhile, Microsoft released a cumulative security update for Internet Explorer that fixes the flaw, as well as seven other security vulnerabilities that would allow an attacker to remotely execute code on a victim's computer." Really, Wired? That late in the article, you gloss over "seven other vulnerabilities" that would allow remote code execution? And worse, you don't point out that Microsoft was informed of five of them BEFORE AURORA?

Seriously, I am the first one to hold Microsoft over the flames for bad practices, but that goes beyond my boundaries. If you are going to take them to task over all this, at least do it right. SIX CODE EXECUTION VULNERABILITIES that they KNEW ABOUT FOR SIX MONTHS. Beating them up over just one is amateur hour in this curmudgeonly world.

Source: OSVDB.org.


Saturday, September 5, 2009

Microsoft minimiza la vulnerabilidad de SQL Server

Microsoft pone en duda la gravedad de una vulnerabilidad en su servidor SQL de base de datos que los investigadores de seguridad dicen expone contraseñas administrativas. La vulnerabilidad, descubierta por Sentrigo, puede ser explotada remotamente en SQL Server 2000 y 2005.

Microsoft minimiza el defecto de seguridad en SQL Server que podría ser explotado por alguien con privilegios administrativos para ver las contraseñas de los usuarios que están sin cifrar.

La vulnerabilidad se descubrió el año pasado por el fabricante de seguridad de base de datos Sentrigo; cuando uno de sus investigadores notó que la cadena única de su contraseña personal era visible en la memoria. Desde entonces, se contacto a Microsoft y se desencadeno una de idas y vuelta entre Sentrigo y Microsoft, que sostiene que la vulnerabilidad no es un problema porque se requiere acceso administrativo.

Mientras funcionarios de Sentrigo admiten que acceso administrativo es necesario para un explotar al trabajo, también sostienen que muchas aplicaciones están desplegadas con privilegios administrativos, lo que significa que hackers podrían utilizar una inyección de SQL y con esta vulnerabilidad para acceder a contraseñas administrativas.

"Las contraseñas utilizadas para conectarse al servidor del MS SQL se almacenan en memoria con texto claro" explicado por el CTO de Sentrigo, Slavik Markovich. "Estas no se borran hasta que se reinicia el servidor del SQL, así que puede en quedar en memoria durante semanas o meses en ambientes de producción. Es algo fácil descargar la memoria y ver su contenido en busca de nombres de usuario y contraseñas".

En el caso de SQL Server 2000 y 2005, los atacantes puede explotar la situación remotamente. Hay algunos procesos de mitigación para los usuarios de SQL Server 2008 porque Microsoft eliminó la utilidad DBCC. Sin embargo, con conexiones locales todavía se puede explotar.

Pese a ello, Microsoft sostiene que la vulnerabilidad es mucho ruido y pocas nueces.

Microsoft ha investigado a fondo reclamaciones de vulnerabilidades en SQL Server y encontraron que estos no son vulnerabilidades que requieren de Microsoft emita una actualización de seguridad. Como se ha mencionado por los investigadores de seguridad, en el escenario en cuestión, un atacante necesitaría derechos administrativos en el sistema atacado.

"Un atacante que tiene derechos administrativos ya tiene completo control del sistema y puede instalar programas; ver, cambiar o borrar datos; o crear nuevas cuentas con plenos derechos de usuario", agregaron desde Microsoft.

Si bien los administradores pueden normalmente restablecer una contraseña de usuario si es necesario, mejores prácticas de seguridad no permiten incluso a los administradores ver la verdadera contraseñas de otros usuarios, oficiales de Sentrigo dicen: este es un problema aún mayor ya que muchas empresas necesitan cumplir con diversas normas y reglamentos que exigen estricta separación de funciones, algo que es claramente violado por compartir todos las contraseñas de los usuarios con los administradores.

En respuesta a la situación, el fabricante de seguridad ha publicado un utilitario gratuito para borrar estas contraseñas. La utilidad puede ser descargada a partir de hoy de la pagina Web de Sentrigo.

Fuente: SeguInfo.

Friday, September 4, 2009

Microsoft reports attacks using IIS vulnerability

A vulnerability in Microsoft's software for housing Web sites is now being used for "limited attacks" on the servers it's running on, the company said Friday.

Microsoft disclosed the Internet Information Services (IIS) vulnerability on Monday and said Friday it's still working on a security update to fix the problem. In the meantime, the advisory has instructions for a workaround, including disabling various elements of the vulnerable FTP (File Transfer Protocol) service to upload and download files.

According to the advisory, the vulnerability could let somebody run arbitrary code on a server using FTP on IIS 5.0 and conduct a denial-of-service attack using FTP on IIS 5.1, 6.0, and 7.0. The present version 7.5 isn't affected, though, and FTP 7.5 can be downloaded and installed on IIS 7.0 to protect it.

"Customers should be aware that the Download Center has FTP 7.5 available for Windows Vista and Windows Server 2008. FTP 7.5 is not vulnerable to any of these exploits," said Alan Wallace, senior communications manager for Microsoft's security response communications team, in a statement.

Initially, the company said it was investigating a vulnerability only with versions 5 and 6 of IIS

Source: cnet.