Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Whitehats pierce giant hole in Microsoft security shield
The Register ^ | 18 April 2011 | Dan Goodin

Posted on 04/18/2011 11:56:11 AM PDT by ShadowAce

In late December, Microsoft researchers responding to publicly posted attack code that exploited a vulnerability in the FTP service of IIS told users it wasn't much of a threat because the worst it probably could do was crash the application.

Thanks at least in part to security mitigations added to recent operating systems, attackers targeting the heap-overrun flaw had no way to control data that got overwritten in memory, IIS Security Program Manager Nazim Lala blogged. It was another victory for Microsoft's defense-in-depth approach to code development, which aims to make exploitation harder by adding multiple security layers.

However, it turned out that wasn't the case. White-hat hackers Chris Valasek and Ryan Smith of security firm Accuvant Labs soon posted screenshots showing they had no trouble accessing parts of memory in the targeted machine that the protection – known as heap exploitation mitigation – should have made off limits. With that hurdle cleared, they had shown the IIS zero-day bug was much more serious than Microsoft's initial analysis had let on.

“The point was proven that you could actually start to execute code, as opposed to them saying: 'Don't worry about it. It can only crash your server',” Valasek, who is a senior research scientist for Accuvant, told The Register.

Up until now, their technique for bypassing the heap protection has been a mystery outside of a small circle of researchers. On Saturday, Valasek and Smith, the latter who is Accuvant's chief research scientist, shared their secret at the Infiltrate security conference in Miami Beach.

Heap-exploitation mitigation made its Microsoft debut in Service Pack 2 of Windows XP, and has since been refined in later OSes. It works by detecting memory that's been corrupted by heap overflows, and then terminating the underlying process. The technology was a significant advance for Microsoft. Practically overnight, an entire class of vulnerabilities that once allowed attackers to take full control of the targeted operating system were wiped out.

Running on the newer operating systems, the same exploits could do nothing more than crash the buggy application.

Valasek and Smith were able to bypass the mitigation because Microsoft's reworked heap design also included a new feature known as LFH, or low fragmentation heap, which aims to improve speed and performance by providing a new way to point applications to free locations of memory. And for reasons that remain unclear, the new feature didn't make use of the heap-exploitation mitigations.

“They opened up a new path for attackers, so it was great for attackers but bad for the end user,” Smith said. “The back door is locked, so we go in the front door.”

The LFH isn't turned on by default, and it turns out that it often requires a lot of work for an attacker to enable it. In the case of December's IIS vulnerability, they turned it on by invoking several FTP commands in a particular way. With that out of the way, they had no trouble controlling the memory locations on the targeted machine.

Valasek and Smith are quick to point out that bypassing the mitigations requires considerably more effort and skill on the part of the attacker. Five or 10 years ago, it was frequently possible for exploit developers to recycle huge amounts of code when writing a new script. That's not the case now.

“Unlike other exploitation techniques of the past, you need to know more about the underlying operating system and the application that's being run to figure out how to enable [LFH] and how to use it to your advantage,” Valasek said. “You can't blindly go about your business.”

The talk is the latest reminder of the spy-versus-spy nature of security work, in which new protections developed by whitehats are constantly being defeated by blackhats, which then requires whitehats to come up with still newer protections. Researchers have similarly figured out ways to bypass other security mitigations, with techniques such as "JIT-spraying” for address space layout randomization and return oriented programming for data-execution prevention.

Still, the researchers said the mitigations are an essential part of software development – as long as engineers recognize their inherent limitations and don't become complacent.

“As long as the mitigations are there to protect the end user and not to protect the company from having to patch, then they're a good thing because it does make the job harder,” Smith said. “It's a way to buy time.” ®


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: microsoft; vulnerability

1 posted on 04/18/2011 11:56:11 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

Anyone using FTP in a secure or sensitive environment is an idiot.


2 posted on 04/18/2011 11:58:37 AM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

3 posted on 04/18/2011 11:59:31 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #4 Removed by Moderator

To: ShadowAce
Whitehats pierce giant hole in Microsoft security shield

What a ridiculous title, referring to FTP as "Microsoft's security sheild" when it's a file transfer tool that's rarely even used anymore, and gets more milage from those who love pointing out that Microsoft has some ancient freeware code somewhere in Windows. The article comes from a foreign website too of course, typical.

5 posted on 04/18/2011 12:11:12 PM PDT by Golden Eagle (Buy American)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Golden Eagle
Long time, no see, GE!!

Welcome back!

6 posted on 04/18/2011 12:12:43 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ShadowAce

Thanks, looks like neither of us has changed though LOL. At least the frequency of these these types of posts seems to have come down, so hopefully I won’t have to comment much, I’d rather focus on significanly more important matters. Hope you will too, later.


7 posted on 04/18/2011 12:15:46 PM PDT by Golden Eagle (Buy American)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Golden Eagle
What a ridiculous title, referring to FTP as "Microsoft's security sheild" when it's a file transfer tool that's rarely even used anymore, and gets more milage from those who love pointing out that Microsoft has some ancient freeware code somewhere in Windows. The article comes from a foreign website too of course, typical.

I concur. FTP is rarely used anymore for good reason. I just attempted to add remote deposit capability with my bank, for my business, which would have permitted me to deposit checks using a scanner in my office - negating the need for frequent trips to the bank. I got to foraging around in the accompanying software and realized that it relied on FTP to transmit all the data back to the bank. Palm.....Forehead. Needless to say, I boxed it back up and dropped it off with my hand carried deposit that afternoon.

8 posted on 04/18/2011 12:59:29 PM PDT by RobertClark (On a long enough timeline the survival rate for everyone drops to zero.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ShadowAce

When I served in the Navy going on half-a-hundred years ago, enlisted sailors below the rank of Chief Petty Offficer were called whitehats. So I opened the thread looking to see what the new Navy is up to...


9 posted on 04/18/2011 1:12:53 PM PDT by JimRed (Excising a cancer before it kills us waters the Tree of Liberty! TERM LIMITS, NOW AND FOREVER!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Thanks for the ping.


10 posted on 04/18/2011 1:57:10 PM PDT by GOPJ (Understanding the Koran: http://www.citizenwarrior.com/2009/05/terrifying-brilliance-of-islam.html)
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson