Security Flaws in Windows XP Service Pack 2 CSE 7339 9/14/04 By: Saeed Abu Nimeh.

Slides:



Advertisements
Similar presentations
Desktop Value - Introducing Windows XP Service Pack 2 with Advanced Security Technologies Presenter: James K. Murray Title: Information Technologies Consultant.
Advertisements

IMS Client Installation Procedures 1. Copy the Voic Pro from the shared folder on the Voic Pro server. Go to Start, Run, and \\ or \\
Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.
Windows Server 2003 SP1. Windows Server™ 2003 Service Pack 1 Technical Overview Jill Steinberg: Added TM Jill Steinberg: Added TM.
Configuring Windows Internet Explorer 7 Security Lesson 5.
AVG Internet Security 7.5 Product presentation.
Windows XP Service Pack 2 Technical Update. Windows XP Service Pack 2 Technical Workshop Agenda –Security Overview –Introduce Windows XP Service Pack.
Chapter 9: Configuring Internet Explorer. Internet Explorer Usability Features Reorganized user interface Instant Search box RSS support Tabbed browsing.
Windows XP Service Pack 2 Alex Balcanquall Senior Consultant Microsoft Services Organisation.
Changes in Windows XP Service Pack 2
14.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Information for Developers Windows XP Service Pack 2 Information for Developers.
Lesson 19: Configuring Windows Firewall
EDDS Error Handling QP & Reliability Team. 2 EDDS Error Handling 1. In case of ‘Error code: -1’ (refer below captured error message ) EDDS system need.
Windows XP Service Pack 2 and the Microsoft Virtual Machine: Developer Implications Rudi Larno Developer & Platform Group Microsoft BeLux.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 2 Craig Schofield Microsoft Ltd. UK September.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Security of Communication & IT systems Bucharest, 21 st September 2004 Stephen McGibbon Chief Technology Officer, Eastern Europe, Russia & CIS Senior Director,
Microsoft Windows XP SP2 for Developers Rafal Lukawiecki Strategic Consultant Project Botticelli Ltd This session is based.
2851A_C01. Microsoft Windows XP Service Pack 2 Security Technologies Bruce Cowper IT Pro Advisor Microsoft Canada.
Microsoft October 2004 Security Bulletins Briefing for Senior IT Managers updated October 20, 2004 Marcus H. Sachs, P.E. The SANS Institute October 12,
Using Application Compatibility Toolkit (ACT) 4.0 to Manage Application Compatibility on XP SP2 and Server SP1 Corey Hynes DSK304.
Microsoft ® Official Course Module 9 Configuring Applications.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Module 1: Installing Windows XP Professional. Overview Manually Installing Windows XP Professional Automating a Windows XP Professional Installation Using.
Security in the industry H/W & S/W What is AMD’s ”enhanced virus protection” all about? What’s coming next? Presented by: Micha Moffie.
Thrive Installation.
Configuring the MagicInfo Pro Display
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Information for Developers Windows XP Service Pack 2 Information for Developers Tony Goodhew Product manager Developer Division Microsoft Corp
Tutorial 11 Installing, Updating, and Configuring Software
Computers Are Your Future Eleventh Edition Chapter 4: System Software Copyright © 2011 Pearson Education, Inc. Publishing as Prentice Hall1.
Windows Vista Security Center Chapter 5(WV): Protecting Your Computer 9/17/20151Instructor: Shilpa Phanse.
COMPREHENSIVE Windows Tutorial 5 Protecting Your Computer.
®® Microsoft Windows 7 Windows Tutorial 5 Protecting Your Computer.
Troubleshooting Windows Vista Security Chapter 4.
3-Protecting Systems Dr. John P. Abraham Professor UTPA.
DIT314 ~ Client Operating System & Administration CHAPTER 2 INTRODUCTION TO WINDOWS XP PROFESSIONAL Prepared By : Suraya Alias.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
1 Internet Browsing Vulnerabilities and Security ECE4112 Final Lab Ye Yan Frank Park Scott Kim Neil Joshi.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Microsoft Internet Explorer and the Internet Using Microsoft Explorer 5.
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
OFC290 Information Rights Management in Microsoft Office 2003 Lauren Antonoff Group Program Manager.
C HAPTER 2 Introduction to Windows XP Professional.
What’s New in WatchGuard XCS v9.1 Update 1. WatchGuard XCS v9.1 Update 1  Enhancements that improve ease of use New Dashboard items  Mail Summary >
Module 5: Configuring Internet Explorer and Supporting Applications.
Operating Systems Foundation Computing Half the people you know are below average.
Module 6: Managing Client Access. Overview Implementing Client Access Servers Implementing Client Access Features Implementing Outlook Web Access Introduction.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Windows XP Service Pack 2 Customer Awareness Workshop Trustworthy Computing – XP SP2 Technical Overview Craig Schofield Microsoft.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 1 Craig Schofield Microsoft Ltd. UK September.
NetTech Solutions Supporting Users and Troubleshooting Desktop Applications on Microsoft Windows XP Instructor Richard Fredrickson.
W elcome to our Presentation. Presentation Topic Virus.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK
Active X and Signed Applets Chad Bollard. Overview ActiveX  Security Features  Hidden Problems Signed Applets  Security Features  Security Problems.
ITMT Windows 7 Configuration Chapter 7 – Working with Applications.
XPSP2 “Basic Gotchas” Security Center “Welcome” –May be confusing –Gives a “No Antivirus” warning for machines with SAV which have NOT been patched for.
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Windows Vista Configuration MCTS : Network Security.
Information About Microsoft’s August 2004 Security Bulletins August 13, 2004 Feliciano Intini, CISSP, MCSE Security Advisor Premier Security Center Microsoft.
For more information on Rouge, visit:
11 DEPLOYING AN UPDATE MANAGEMENT INFRASTRUCTURE Chapter 6.
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
Agenda The current Windows XP and Windows XP Desktop situation
Using Software Restriction Policies
Implementing Advanced Server and Client Security
Presentation transcript:

Security Flaws in Windows XP Service Pack 2 CSE /14/04 By: Saeed Abu Nimeh

Outline Microsoft Introducing SP2 Collaboration with the industry What’s New in SP2 Heise Security Advisory Microsoft’s Response References

Microsoft Introducing SP2 Microsoft releases a SP every year for Win XP. It was supposed to be released in the first half of the year. Friday, August 6, 2004 SP2 was released. Gates: “SP2 modifies less than 5 percent of the nearly 3-year-old operating system”.

Microsoft Introducing SP2 Gates: “SP2 2 is a significant step in delivering on our goal to help customers make their PCs better isolated and more resilient in the face of increasingly sophisticated attacks“. “It is the result of sustained investments in innovation and extensive industry collaboration.“

Collaboration with the industry Windows Security Center: Symantec: Antivirus, Firewall and Intrusion Prevention security solutions are compatible with SP2. Data execution prevention: Intel: Improve security PC platform by Execute Disable Bit and Microsoft's Data Execution Prevention AMD: Support for AMD Athlon 64-bit desktop and mobile processors Preloaded PCs: Working with computer manufacturers: Dell, HP and IBM to ship machines preloaded with SP2 beginning in September and October.

What’s New in SP2 SP2 reduces the most common attack vectors four ways: Network protection Memory protection More secure browsing security and Safer message handling Improved computer maintenance

Network Protection Windows Firewall (Internet Connection Firewall-ICF): Is enabled by default. The firewall turns on very early in the system boot cycle, and turns off very late in the shutdown cycle. Enhanced Group Policy settings to support IPv6. Remote Procedure Call (RPC): Permissions to block services. Distributed Component Object Model (DCOM): Restrictions to reduce the risk, only authenticated administrators can remotely activate and launch COM components. Disabling the Windows Messenger Service by default

Memory protection Execution Protection (NX) Marks all memory locations in a process as non-executable unless the location explicitly contains executable code. Only processors that support NX are the 64-bit AMD K8 and Intel Itanium. Sandboxing: Stack: All binaries in the system recompiled with buffer security checks “enabled” to allow the runtime libraries to catch stack buffer overruns, Heap: "cookies" have been added to the heap to allow the runtime libraries to catch most heap buffer overruns

security New Outlook Express to block images and external content in HTML . View in plain text mode Attachment Execution Service (AES) It looks at the file extension. It can look up the associated application for a given MIME type and file extension

Secure browsing Add-on Management Tool View and control the list of add-ons that can be loaded by IE. Shows the presence of some add-ons that were previously not shown and could be very difficult to detect. Add-on Crash Detection: Detect crashes in IE that are related to an add-on, and gives the user the option to disable add-ons Attachment Execution Service (AES) Can not view ActiveX script in IE. Pop-up Manager: Block Pop-ups

Computer Maintenance Windows Update 5 Scan for, download, and install only the critical and security updates Windows Installer 3 Enhanced inventory functions that identify what patch components do and don't need to be downloaded, Supports Microsoft's “delta compression” technology, which makes patches smaller

Heise Security Advisory August, 13, 2004 Heise Security posted an advisory “Flaws in SP2 security features” by Jürgen Schmidt There are two flaws: a cmd issue: The Windows command shell cmd ignores zone information and starts executables without warnings. The caching of ZoneIDs in Windows Explorer: Windows Explorer does not update zone information properly when files are overwritten.

The cmd Issue The command shell cmd.exe ignores the ZoneID of files: cmd /c evil.exe cmd /c evil.gif Execute the files without warning, regardless of its ZoneID with an attachment Access.gif You can not access it, unless its opened from cmd

Windows Explorer caching of ZoneIDs Windows Explorer caches the result of ZoneID lookups. If a file is overwritten, Explorer does not properly update this cached information to reflect the new ZoneID. This allows spoofing of trusted or non- existant ZoneIDs by overwriting files with trusted or non-existent ZoneIDs.

Windows Explorer caching of ZoneIDs Copy notepad to a new file. > copy c:\windows\notepad.exe test.exe Open test.exe in Explorer: no warning. evil.exe is a file saved from an attachment and has ZoneID=3. Check with your editor by opening "evil.exe:Zone.Identifier". It displays: ZoneID=3 Open evil.exe in Explorer: you will be warned.

Windows Explorer caching of ZoneIDs Overwrite the copy of notepad.exe: > copy evil.exe test.exe test.exe:Zone.Identifier displays: ZoneID=3 Open test.exe in Explorer: no warning! test.exe is launched without warning despite of its ZoneID=3. In the file properties, Explorer shows the correct notice about its origin, but for opening the file the old ZoneID-status is used. Doublecheck: Kill the Explorer task, restart it and launch test.exe: you will be warned.

Microsoft’s Response "We have investigated your report, as we do with all reports, however in this case, we don't see these issues as being in conflict with the design goals of the new protections. We are always seeking improvements to our security protections and this discussion will certainly provide additional input into future security features and improvements, but at this time we do not see these as issues that we would develop patches or workarounds to address."

References Wired News, Microsoft Releases Service Pack 2, URL: l l Microsoft Press, Microsoft Releases SP2 with Advanced Security Technologies to Computer Manufacturers, URL: 06WinXPSP2LaunchPR.asp 06WinXPSP2LaunchPR.asp Windows XP Service Pack 2 Overview, White Paper, February 2004 Windows XP Service Pack 2, URL: Steve Friedl, Analysis of Microsoft XP Service Pack 2, URL: Heise Security Advisory, URL: