محمد المصري
23-12-2011, 09:40 PM
بسم الله الرحمن الرحيم
السلام عليكم ورحمة الله وبركاتة ..
انتشرت في الفترة السابقة ثغرة في نظام تشغيل الوندوز تسمح بتنفيذ أكواد على الأجهزة المستهدفة. تحديدا من خلال التعامل مع ملفات الإختصارات lnk . فحبيت أسلط الضوء علي هذا الموضوع.
( ملف الـ Explorer.EXE بمجرد ما يشوف ملف الاختصار .lnk يقوم بتنفيذ ما داخلة تلقائيا )
علما بأن الثغرة فعالة علي الإصدارات التالية :
رمز PHP:
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 1 and Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for Itanium-based Systems
بالطبع لن نطرق عن الاستغلال لكن يكون الاستغلال الضار يكون بإضافة ****************lcode يقوم بتحميل أو تنفيذ ملفات ضارة مرفقة مع ملف الإختصار, وثق بأنها ستعمل تلقائيا .
هناك حل مؤقت للحماية من الثغرة وهو نقلا عن أي سيكورتي :
نقوم في البداية بفتح محرر التسجيل regedit والذهاب إلى المفتاح التالي:
رمز PHP:
HKEY_CLASSES_ROOT\lnkfile\****************lex\Icon Handler
http://www.vb.6ocity.net/images/imgcache/2011/12/11743.jpg
ومن ثم نقوم بتغيير إسم المفتاح من IconHandler إلى اي إسم آخر مثل : IconHandler-bak , ومن ثم نقوم بإعادة تشغيل الجهاز.
بإعادة التشغيل نجد أن كل الإختصارات بدون أيقوناتها ونستطيع ملاحظة أن الثغرة لم تعد تعمل بسبب التعطيل الحاصل:
http://www.vb.6ocity.net/images/imgcache/2011/12/11744.jpg
قبل تحديث النظام وترقيع الثغرة ضع في حسبانك أن تعيد مفتاح IconHandler إلى اسمه الأصلي لأن الترقيع قد يتعامل مع المفتاح بشكل من الأشكال ولا تنس إعادة التشغيل =)
فيديوهات لخطورة الثغرة ..
OQ2TCIUaw8A
6304Q0YoiBg
روابط ذات صلة ..
Microsoft Security Advisory (2286198): Vulnerability in Windows ****************l Could Allow Remote Code Execution (http://technet.microsoft.com/en-us/security/advisory/2286198)
Microsoft Security Bulletin MS10-046 - Critical : Vulnerability in Windows ****************l Could Allow Remote Code Execution (2286198) (http://technet.microsoft.com/en-us/security/bulletin/MS10-046)
MS10-046: Vulnerability in Windows ****************l could allow remote code execution (http://support.microsoft.com/kb/2286198)
Mitigating .LNK Exploitation With SRP « Didier Stevens (http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/)
More Analysis of Case LNK Exploit - F-Secure Weblog : News from the Lab (http://www.f-secure.com/weblog/archives/00001987.html)
Mu7ammeD
م ن ق و ل
السلام عليكم ورحمة الله وبركاتة ..
انتشرت في الفترة السابقة ثغرة في نظام تشغيل الوندوز تسمح بتنفيذ أكواد على الأجهزة المستهدفة. تحديدا من خلال التعامل مع ملفات الإختصارات lnk . فحبيت أسلط الضوء علي هذا الموضوع.
( ملف الـ Explorer.EXE بمجرد ما يشوف ملف الاختصار .lnk يقوم بتنفيذ ما داخلة تلقائيا )
علما بأن الثغرة فعالة علي الإصدارات التالية :
رمز PHP:
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 1 and Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for Itanium-based Systems
بالطبع لن نطرق عن الاستغلال لكن يكون الاستغلال الضار يكون بإضافة ****************lcode يقوم بتحميل أو تنفيذ ملفات ضارة مرفقة مع ملف الإختصار, وثق بأنها ستعمل تلقائيا .
هناك حل مؤقت للحماية من الثغرة وهو نقلا عن أي سيكورتي :
نقوم في البداية بفتح محرر التسجيل regedit والذهاب إلى المفتاح التالي:
رمز PHP:
HKEY_CLASSES_ROOT\lnkfile\****************lex\Icon Handler
http://www.vb.6ocity.net/images/imgcache/2011/12/11743.jpg
ومن ثم نقوم بتغيير إسم المفتاح من IconHandler إلى اي إسم آخر مثل : IconHandler-bak , ومن ثم نقوم بإعادة تشغيل الجهاز.
بإعادة التشغيل نجد أن كل الإختصارات بدون أيقوناتها ونستطيع ملاحظة أن الثغرة لم تعد تعمل بسبب التعطيل الحاصل:
http://www.vb.6ocity.net/images/imgcache/2011/12/11744.jpg
قبل تحديث النظام وترقيع الثغرة ضع في حسبانك أن تعيد مفتاح IconHandler إلى اسمه الأصلي لأن الترقيع قد يتعامل مع المفتاح بشكل من الأشكال ولا تنس إعادة التشغيل =)
فيديوهات لخطورة الثغرة ..
OQ2TCIUaw8A
6304Q0YoiBg
روابط ذات صلة ..
Microsoft Security Advisory (2286198): Vulnerability in Windows ****************l Could Allow Remote Code Execution (http://technet.microsoft.com/en-us/security/advisory/2286198)
Microsoft Security Bulletin MS10-046 - Critical : Vulnerability in Windows ****************l Could Allow Remote Code Execution (2286198) (http://technet.microsoft.com/en-us/security/bulletin/MS10-046)
MS10-046: Vulnerability in Windows ****************l could allow remote code execution (http://support.microsoft.com/kb/2286198)
Mitigating .LNK Exploitation With SRP « Didier Stevens (http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/)
More Analysis of Case LNK Exploit - F-Secure Weblog : News from the Lab (http://www.f-secure.com/weblog/archives/00001987.html)
Mu7ammeD
م ن ق و ل