<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Vulnerabilities &amp;amp; Exploits</title><link>http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx</link><description>Tags: Vulnerabilities &amp;amp; Exploits</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Zero day in MSVIDCTL.DLL</title><link>http://pandalabs.pandasecurity.com/archive/Zero-day-in-MSVIDCTL.DLL.aspx</link><pubDate>Wed, 08 Jul 2009 07:21:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1014</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1014.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1014</wfw:commentRss><description>&lt;p&gt;A couple of days ago we started spotting a new vulnerability affecting Microsoft Video ActiveX Control. Even though it&amp;#39;s been said there are thousands of web sites affected, they are only a&amp;nbsp;few dozens and most of them are in China: Anyway, it is a matter of time to see this attack expanding worldwide. We&amp;#39;ve seen this zero day installing a Lineage Trojan, but this could change and cybercriminals could install any kind of malware. &lt;/p&gt;&lt;p&gt;Microsoft has published an &lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank"&gt;advisory&lt;/a&gt; with a workaround while they prepare a final solution. An important message to everyone: please apply this workaround ASAP. &lt;/p&gt;&lt;p&gt;If you are a Panda user with TruPrevent Technologies, then you are not in a hurry, as it is proactively stopping it. The best thing is that you don&amp;#39;t need to install some kind of beta or technology preview, it just works in all of our consumer and corporate products as long as they have enabled TruPrevent. No matter which version you have installed, it covers not only the brand new 2010 products but any old version with TruPrevent. &lt;/p&gt;&lt;p&gt;Sean-Paul shows you here why and how you are protected:&lt;/p&gt;&lt;p&gt;&lt;a href="http://vimeo.com/5500638" target="_blank"&gt;&lt;img height="377" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/08/TruPrevent.jpg" width="505" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1014" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category></item><item><title>MS09-008. Does the patch work?</title><link>http://pandalabs.pandasecurity.com/archive/MS09_2D00_008.-Does-the-patch-work_3F00_.aspx</link><pubDate>Sat, 14 Mar 2009 12:47:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:984</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/984.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=984</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The vulnerability MS09-008 affects the DNS server, more specifically WPAD (Web Proxy Autodiscovery Protocol) registration. This is a service that allows automatic configuration of proxy settings of the computers wihin a network without user intervention. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This vulnerability could be used to launch &amp;quot;man-in-the-middle&amp;quot; attacks on Windows DNS servers. The web browsers of the PCs in the network are configured through these WPAD entries, so a user that is getting the proxy configuration automatically could be redirected to a malicious proxy and the attacker will have access to all the traffic of the user. To perform this attack, the attacker could insert a WPAD entry in the DNS server when dynamic updates are enabled. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;As a part of the solution to this vulnerability, Microsoft creates two new values in the registry under the key HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters, as you can see in the following screenshot:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="109" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/03/13/registry.jpg" style="width:498px;height:109px;" width="498" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Once created these values in the registry, if anyone tries to launch a &amp;ldquo;man-in-the-middle&amp;rdquo; attack it won&amp;rsquo;t success, as the system will block petitions to the WPAD entry, unless this entry had not been created before applying the patch. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Usually, if you are vulnerable to an attack and you patch the system you feel safe. For instance, all of you know about Conficker, which infects the system using the vulnerability MS08-067. Even if you have been previously infected, you can apply the patch and you won&amp;rsquo;t be infected anymore through this vulnerability. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;However, in the case of MS09-008 patch it doesn&amp;rsquo;t work in the same way; even if we have applied the patch, if we were already attacked through this vulnerability, it doesn&amp;rsquo;t solve the problem and the &amp;ldquo;man-in-the-middle&amp;rdquo; attacks will continue. Why? Because in that case the data in the value GlobalQueryBlockList created when the patch is applied is &amp;ldquo;isatap&amp;rdquo; instead of &amp;ldquo;wpad isatap&amp;rdquo;, so the queries to WPAD are not being blocked.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;To sum up: in case a successful attack has already taken place before applying the patch, your traffic can be being redirected to a malicious proxy. Then, even if you apply the patch, the issue is not completely solved, and the malicious proxy will stay there &amp;ldquo;sniffing&amp;rdquo; all your traffic. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;To solve this, it is only needed to add in the registry to the value GlobalQueryBlockList the data wpad and restart the DNS service.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Microsoft guys have blogged about this, you can find more information &lt;a href="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Kudos to David Sanchez for the research.&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=984" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category></item><item><title>Microsoft Updates for January</title><link>http://pandalabs.pandasecurity.com/archive/Microsoft-Updates-for-January.aspx</link><pubDate>Wed, 14 Jan 2009 15:25:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:949</guid><dc:creator>Xabier Francisco</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/949.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=949</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="MS09-001" height="55" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/01/14/MS09-001.January2009.JPG" style="width:518px;height:55px;" title="MS09-001" width="518" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In the first security bulletin of the year 2009, MS09-001, Microsoft has published several critical updates which resolve 2 privately reported vulnerabilities and a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) protocol. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;If exploited successfully, an attacking user could execute remote code on the system, and could view, change or delete data, or create new accounts with full user rights.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This security update has been rated as critical for all the versions of Microsoft Windows 2000, Windows XP and Windows 2003 and as moderate for all the versions of Windows Vista and Windows Server 2008.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;We remind you that in order to improve the security level of your computer against known and unknown network vulnerabilities, you can stop or block the access to any network service you don&amp;rsquo;t use by using a properly configured firewall or by disabling the network services that are not used in the system.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Although in PandaSecurity we work daily on how to improve our products in order to protect our clients from these new vulnerabilities, we always recommend to install as soon as possible the security patches published in the Microsoft&amp;rsquo;s security bulletins, as well as other security updates that may affect other products installed on the same system.&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;MS09-001&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;- Vulnerabilities in SMB Could Allow Remote Code Execution&lt;br /&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=949" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/PandaLabs/default.aspx">PandaLabs</category></item><item><title>Sony's Home hacked</title><link>http://pandalabs.pandasecurity.com/archive/Sony_2700_s-Home-hacked.aspx</link><pubDate>Fri, 19 Dec 2008 12:37:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:943</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/943.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=943</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;It is not that someone has hacked Sony CEO&amp;#39;s house, we are talking about the Sony Playstation Home:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;img height="332" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/19/playstation-home-logo.jpg" style="width:397px;height:332px;" width="397" /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://en.wikipedia.org/wiki/PlayStation_Home" title="Home in Wikipedia" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Home&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; is&amp;nbsp;a virtual world for PlayStation 3 users, where they can interact with other gamers, create their own avatars, etc.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;We&amp;#39;ve seen it &lt;/font&gt;&lt;a href="http://www.telegraph.co.uk/scienceandtechnology/technology/technologynews/3793715/PlayStation-Home-hacked.html" title="PlayStation Home hacked" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;and this opens a totally new world for cybercrooks, as it could lead to identity theft and malware spreading.&amp;nbsp;A user could even upload, download&amp;nbsp;or delete any file within the Home server (!)&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=943" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category></item><item><title>So what's all this talk of Clickjacking?</title><link>http://pandalabs.pandasecurity.com/archive/So-what_2700_s-all-this-talk-of-Clickjacking_3F00_.aspx</link><pubDate>Tue, 30 Sep 2008 17:30:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:914</guid><dc:creator>Ryan Sherstobitoff</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/914.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=914</wfw:commentRss><description>&lt;p&gt;So there has been a lot of talk recently about this new cross-browser vulnerability known as &amp;ldquo;Clickjacking&amp;rdquo;, but what is the potential impact of such a vulnerability to users abroad? &lt;/p&gt;&lt;p&gt;Well essentially the exploit allows a hacker to take control of the links that your browser visits and thus if you come in contact with a malicious site or site that is tainted with malicious code (either through spam, some site tainted by a SQL injection, etc), it then gives the hackers the ability to &amp;lsquo;capture&amp;rsquo; your clicks and thus trick you into clicking on links you may have not intended on clicking. At this time technical details are a little sketchy in terms of information regarding specific exploit code, but some information is available &lt;a href="http://jeremiahgrossman.blogspot.com/2008/09/cancelled-clickjacking-owasp-appsec.html"&gt;here&lt;/a&gt; and &lt;a href="http://ha.ckers.org/blog/20080915/clickjacking/"&gt;here&lt;/a&gt;.&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;One could only guess what could happen next once you are forced to click on a link such as installation of a Banker Trojan or other malware is &lt;span class="SpellE"&gt;certaintly&lt;/span&gt; a possibility&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=914" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category></item><item><title>VML, Viking and Lineage... Any further bids?</title><link>http://pandalabs.pandasecurity.com/archive/VML_2C00_-Viking-and-Lineage_2E002E002E00_-Any-further-bids_3F00_.aspx</link><pubDate>Fri, 20 Oct 2006 15:12:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:7</guid><dc:creator>egonzalez</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/7.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=7</wfw:commentRss><description>We have been aware of a site hosting a page that exploits the VML vulnerability. Through this exploit, it downloads a W32/Viking variant. This Viking downloads several Trj/Lineage variants. And finally, these Lineage variants are responsible for gathering victim&amp;#39;s data, such as passwords. Have a careful surfing...&lt;br /&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=7" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Cybercrime/default.aspx">Cybercrime</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category></item></channel></rss>