Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 21, 2013, 06:25:37 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663457
Posts
70535
Topics
145193
Members
Latest Member:
domoc
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
CIS 5.9 bypassed by java_rhino exploit
« previous
next »
Pages:
1
2
[
3
]
4
5
Author
Topic: CIS 5.9 bypassed by java_rhino exploit (Read 15995 times)
ssj100
Comodo's Hero
Offline
Posts: 481
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #30 on:
December 22, 2011, 01:33:14 PM »
Quote from: webbie146 on December 22, 2011, 10:19:33 AM
Tested sandboxie for someone too. Sandboxed the browser, and emptied the sandbox.
The connection between the hacker and victim PC is interrupted. Sandboxie is effective against this exploit.
That's interesting - so the connection was able to be established within the sandbox? Could screenshots etc be taken? Exactly what could be done to the victim PC?
Exactly which file is the payload?
«
Last Edit: December 22, 2011, 01:35:11 PM by ssj100
»
Logged
Sandboxie + LUA + SRP + DEP + SuRun
Windows Firewall + NAT Router + IPSec (on-demand)
VirtualBox (on-demand)
Drive SnapShot (on-demand)
webbie146
Comodo's Hero
Offline
Posts: 262
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #31 on:
December 22, 2011, 04:56:30 PM »
Quote from: ssj100 on December 22, 2011, 01:33:14 PM
That's interesting - so the connection was able to be established within the sandbox? Could screenshots etc be taken? Exactly what could be done to the victim PC?
Exactly which file is the payload?
Yes, the connection can still be established. Basically most features are still working. Some things are not working, like injecting into another process. Screenshot and the key-logger still work.
Exactly what could be done to the victim PC?
A few examples:
Screenshot
webcam screenshot
key-logger
PC info/process list
uploading/downloading files
Basically anything you can think of can be done.
Java rhino = exploit
java/meterpreter/reverse_http = payload type
The payload can be a lot of different types.
You can read a bit about how it works here:
http://www.offensive-security.com/metasploit-unleashed/Metasploit_About_Meterpreter
Btw: I send the exploit, and 14 other undetected browser exploits to egemen. This way signatures can be created
«
Last Edit: December 22, 2011, 05:11:25 PM by webbie146
»
Logged
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #32 on:
December 22, 2011, 05:29:37 PM »
quick question, seeing as you are on the same network when you did the test did you select in CIS public network or did you select home. Reason I am asking becasue if you select home cis allows everything through the firewall. Just an idea maybe.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
webbie146
Comodo's Hero
Offline
Posts: 262
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #33 on:
December 22, 2011, 05:35:48 PM »
Quote from: languy99 on December 22, 2011, 05:29:37 PM
quick question, seeing as you are on the same network when you did the test did you select in CIS public network or did you select home. Reason I am asking becasue if you select home cis allows everything through the firewall. Just an idea maybe.
I think I selected work, not sure though. Will look at this
Logged
MorphOS REBOL
Comodo's Hero
Offline
Posts: 831
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #34 on:
December 22, 2011, 06:55:34 PM »
even more embarrassed by now, at least atm.
Cheers, REBOL.
Internet seems to be not that secure atfm.
Let's return to our farms itm.
Logged
ssj100
Comodo's Hero
Offline
Posts: 481
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #35 on:
December 22, 2011, 07:43:00 PM »
Quote from: webbie146 on December 22, 2011, 04:56:30 PM
Yes, the connection can still be established. Basically most features are still working. Some things are not working, like injecting into another process. Screenshot and the key-logger still work.
Exactly what could be done to the victim PC?
A few examples:
Screenshot
webcam screenshot
key-logger
PC info/process list
uploading/downloading files
Basically anything you can think of can be done.
Java rhino = exploit
java/meterpreter/reverse_http = payload type
The payload can be a lot of different types.
You can read a bit about how it works here:
http://www.offensive-security.com/metasploit-unleashed/Metasploit_About_Meterpreter
Btw: I send the exploit, and 14 other undetected browser exploits to egemen. This way signatures can be created
Actually I was asking what exactly can be done to the victim's PC when the exploit is triggered inside the sandboxed browser. Not sure if you understand how Sandboxie works, but nothing should be able to "break out" of the sandbox. I'm not worried about keylogging etc taking place within the sandbox, but that's where it should end - the "REAL" system should not be modified. And therefore once you terminate programs within the sandbox or delete the sandbox, it will be as if nothing has happened.
It will be interesting to see if you can eg. install programs into the REAL system (C:\Program Files\etc) or write into the REAL system with that connection, despite Sandboxie.
Also, what Port(s) does the connection use?
Logged
Sandboxie + LUA + SRP + DEP + SuRun
Windows Firewall + NAT Router + IPSec (on-demand)
VirtualBox (on-demand)
Drive SnapShot (on-demand)
naren
Comodo's Hero
Offline
Posts: 3860
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #36 on:
December 23, 2011, 06:23:52 AM »
Is it possible to test it with Valkyire & CIMA?
Does the latest Java secures the system with this exploit?
Thanxx testing with UnThreat.
Regards
Naren
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #37 on:
December 23, 2011, 06:56:15 AM »
Quote from: naren on December 23, 2011, 06:23:52 AM
Is it possible to test it with Valkyire & CIMA?
Think not it's not a PE, so they won't be tested.
Quote
Does the latest Java secures the system with this exploit?
Yes 6u29 solves this issue
Quote
Thanxx testing with UnThreat.
Regards
Naren
So you lost the bet
what are you going to do now because of that
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
webbie146
Comodo's Hero
Offline
Posts: 262
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #38 on:
December 23, 2011, 07:47:02 AM »
Quote from: ssj100 on December 22, 2011, 07:43:00 PM
Actually I was asking what exactly can be done to the victim's PC when the exploit is triggered inside the sandboxed browser. Not sure if you understand how Sandboxie works, but nothing should be able to "break out" of the sandbox. I'm not worried about keylogging etc taking place within the sandbox, but that's where it should end - the "REAL" system should not be modified. And therefore once you terminate programs within the sandbox or delete the sandbox, it will be as if nothing has happened.
It will be interesting to see if you can eg. install programs into the REAL system (C:\Program Files\etc) or write into the REAL system with that connection, despite Sandboxie.
Also, what Port(s) does the connection use?
I understand what sandboxie does, i have used it in the past..
Anyways the exploit cannot migrate into another process, ore drop files on the 'real' system because it runs in the sandboxie.
Thing is after the exploit made a connection you could upload a rat (remote administration tool). I could then let the rat upload a file to the sandbox. I could then take over the mouse/keyboard and just copy it to the real disk. After that i could execute the .exe, and the real system would be infected.
It's hard, but can be done.
O and the port depends on how you configure the exploit and payload. It can be any port the attacker wants it to be.
Logged
naren
Comodo's Hero
Offline
Posts: 3860
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #39 on:
December 23, 2011, 07:57:00 AM »
Quote from: Ronny on December 23, 2011, 06:56:15 AM
Think not it's not a PE, so they won't be tested.
Yes 6u29 solves this issue
So you lost the bet
what are you going to do now because of that
Thanxx for the info. Good to know the latest Java keeps the system secure with this exploit.
I think I will bet more & keep on counting how many I win & lose. And I bet this was my very first bet here in Comodo forums & so this makes it 0 & 1, 0 Win & 1 Lost
Thanx
Naren
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #40 on:
December 23, 2011, 09:30:12 AM »
I think i found a way to stop this.
Can you please confirm if it still works if you change the following.
Put <path to java> on always sandbox AND untick file and registry virtualisation on the D+ policy.
This seems to break the spawn of the java.exe that's part of the IE parent to a new process java.exe that is the callback to the exploit server.
I will now make a clean install and verify on stock config also.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
webbie146
Comodo's Hero
Offline
Posts: 262
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #41 on:
December 23, 2011, 09:41:38 AM »
Quote from: Ronny on December 23, 2011, 09:30:12 AM
I think i found a way to stop this.
Can you please confirm if it still works if you change the following.
Put <path to java> on always sandbox AND untick file and registry virtualisation on the D+ policy.
This seems to break the spawn of the java.exe that's part of the IE parent to a new process java.exe that is the callback to the exploit server.
I will now make a clean install and verify on stock config also.
My win7 VM is broken now lol. I will create a new VM with win7 and will test this
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #42 on:
December 23, 2011, 10:27:35 AM »
Just retested with a clean install stock config it needs the following to prevent the exploit.
You have to put Java.exe on
Always Sandbox
as Untrusted else it won't block.
No additional restrictions needed.
Beware I tested this on Win XP, x86, Administrator & Java 6u27.
No clue if java is still 100% functional tough.
1) if you don't use java uninstall it
2) if you have to use java make sure your up2date
«
Last Edit: December 23, 2011, 10:30:59 AM by Ronny
»
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #43 on:
December 23, 2011, 11:11:10 AM »
Quote from: Ronny on December 23, 2011, 10:27:35 AM
No clue if java is still 100% functional tough.
Well just tested a legit Java site and it does break the functionality.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS 5.9 bypassed by java_rhino exploit
«
Reply #44 on:
December 23, 2011, 02:50:00 PM »
Best protection for this version is setting java.exe to run 'Always Sandboxed' on the Defense+ Computer Security Policy.
Sandbox restriction level "Partially limited" restricts most of the things the exploit can do with this single exploit.
It is no longer able to get e.g. process list running this setting, but is still able to make e.g. screenshot.
It can still download and upload files, where file uploads will end up in c:\vritualroot because of the sandbox visualization.
That won't cause much harm cause they won't become active on next reboot.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Tags:
Pages:
1
2
[
3
]
4
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.055 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com