Mindcontroll Forum Index
Mindcontroll Forum Index FAQ Memberlist Search

Mindcontroll Forum Index » Programs/Programming Development » Erase somones hard disk... With a URL!
Post new topic  Reply to topic View previous topic :: View next topic 
Erase somones hard disk... With a URL!
PostPosted: 09-11-2002 06:52 PM Reply with quote
M0nKeY
- Remember -
Joined: 09 Feb 2002
Posts: 1235




A malicious Win-XP Help Center request can easily and silently delete the contents of any directory on your Windows machine, we've learned. Worse, MS has rolled the fix silently into SP1 without making a public announcement. A good sketch of the problem in English, along with a harmless self-test, can be <a href="http://24.78.2.184/helpcenter.htm" target="new">found here</a>, thanks to Mike at http://unity.skankhouse.org who did some tinkering after noticing a tip on a BBS.
<br><br>Another, slightly earlier, mention comes from <a href="http://www.vsantivirus.com/xp-files-del.htm" target="new">VSAntivirus</a>, but the page, unfortunately, is en espaņol, though there are some handy screen shots in their bulletin.
<br><br>The hole was discovered by Shane Hird of Distributed Systems Technology Centre, who first reported it to MS on 25 June 2002. <a href="http://www.security.nnov.ru/search/document.asp?docid=3370" target="new">His bulletin</a>, dated 15 August, offers the most detailed view of the problem. He suggests that fellow bug hunters look more deeply into the Help Center and its mysterious powers, since requests can remotely open files with elevated privileges. He offers a few hints about where one might start probing.
<br><br>To verify the exploit all you need to do is pop the following request into any address bar (IE, Win Explorer, etc): hcp://system/DFS/uplddrvinfo.htm?file://c:\test\* and the directory 'test' will be emptied after a couple of Help Center 'wizard' pages pop up uselessly to distract you.
<br><br>The example works as advertised, so anyone wanting to play with it should create a test directory with copies of files. Of course you can delete your entire root directory with this approach if you so choose. Or someone else's.
<br><br>The exploit is extremely dangerous because it looks to the casual user just like a URL, and can be sent in an e-mail or set up as a link on a Web page. Promising heaps of free pr0n in a busy IRC channel would also likewise be effective.
<br><br>To get rid of the vulnerability, you have two choices. You can install XP's new SP1, which will give Billg remote root privileges on your box by virtue of his new, <a href="http://www.theregister.co.uk/content/4/26517.html" target="new">Trojan EULA</a> (and silently re-enable some services you may have disabled like 'automatic update'); or you can just go to C:\Windows\PCHEALTH\HELPCTR\SYSTEM\DFS\ and find the file uplddrvinfo.htm. This you can simply delete or rename. But beware of installing MS patches later on: these have a funny tendency to restore files and settings outside their immediate purview, back to Redmond defaults.
<br><br>To check it out I did a clean install of XP and verified the exploit on a virgin image. I then installed all of the XP patches and updates except SP1, and it still worked. So SP1 is the only 'official' means of fixing the hole. It's not otherwise been dealt with. Those who object to the SP1 EULA on moral grounds will have to delete or rename uplddrvinfo.htm, and do a search for it after subsequent patching to verify that it's still gone.
<br><br>Problems with the XP Help Center have been known for some time, at least since November 2001, when this exploitable <a href="http://online.securityfocus.com/archive/1/241589" target="new">buffer overflow</a> was first reported. Now the issue has finally been fixed, in the background, with no announcement from Redmond. This means that any XP user who doesn't install SP1, and who never hears of the flaw, will remain vulnerable.

_________________
"Am I a man dreaming of a butterfly or a butterfly dreaming of a man?"
View user's profile Find all posts by %s Send private message Send e-mail Visit poster's website AIM Address

PostPosted: 09-21-2002 08:20 AM Reply with quote
js995
Deletes your posts
Joined: 10 Feb 2002
Posts: 226




good news !

if you *accidentally* installed windows xp using a keygen or FCKGW.. and dont want to use SP1 .. try

http://grc.com/files/XPdite.exe

small 20k exe that replaces the fucked file with the fixed version from SP1

Smile
View user's profile Find all posts by %s Send private message

Erase somones hard disk... With a URL!
 Mindcontroll Forum Index » Programs/Programming Development
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You can vote in polls in this forum
All times are GMT - 5 Hours  
Page 1 of 1  

  
  
 Post new topic  Reply to topic  


Video Games Suck - XXXSwim - Archive
  Powered by phpBB © 2001-2005 phpBB Group. Designed for Trushkin.net | Themes Database