<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 19 Jun 2007 09:09:06 -0000</lastBuildDate><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322434</link><description>Why does IE7 rename .jar files to .zip files when they are download. How can IE7 be configured to download .jar files as .jar files and not as .zip?&lt;br&gt;&lt;br&gt;This is a real annoyance!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Peter</dc:creator><pubDate>Tue, 19 Jun 2007 09:09:06 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322433</link><description>I'm not paying attention to the jar names we're tossing around (and I haven't confirmed anything) but I'm pretty sure you can't just stick the JNI-driven JDirect code in an Applet.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Sun, 29 Apr 2007 14:13:02 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322432</link><description>@COD3R &lt;br&gt;ROTFL. Do you know what a .jar file is? Do you know what an Applet is? Applet QTJava.jar can be automatically downloaded and executed via Java browser</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kull</dc:creator><pubDate>Sun, 29 Apr 2007 05:41:13 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322405</link><description>That all makes sense, and I'm 99.9% sure you're right, but remember, until 3Com publishes the details for this, nobody knows for sure whether killing the jars will work.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Fri, 27 Apr 2007 16:08:24 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322431</link><description>On XP Pro, if unable to disable Java, I believe deleting all instances of QTJava.zip and QTJava.jar will suffice.&lt;br&gt;&lt;br&gt;I mention QTJava.jar because some Java apps appear to copy and/or rename this file to take advantage JRE's default of adding *.jar files into its classpath.&lt;br&gt;&lt;br&gt;The best resource for developing or defeating this vuln is&lt;br&gt;&lt;a href="http://lists.apple.com/archives/quicktime-java" rel="nofollow"&gt;http://lists.apple.com/archives/quicktime-java&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">C0D3R</dc:creator><pubDate>Fri, 27 Apr 2007 16:02:39 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322430</link><description>I have XP Pro SP2 and IE7.  I am going to school online and need java for my classes to work.  So, I cannot disable java.  What else can I do for protection against this?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dixie Scott</dc:creator><pubDate>Thu, 26 Apr 2007 18:43:15 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322429</link><description>We have conducted further analysis and here the results:&lt;br&gt;IE6 an IE7 are not affected &lt;br&gt;Firefox 2.0.0.3 is vulnerable on Mac/Windows/Linux</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Fake Terri Forslof</dc:creator><pubDate>Thu, 26 Apr 2007 09:33:10 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322428</link><description>For starters --- and this is just for starters --- think about things like XSS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 26 Apr 2007 00:37:04 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322427</link><description>Ok,  I may be spiltting hairs here, but doesn't the fact that it is malicious WEB content require some active user interaction?  Browser, email, quicktime app. etc.  The only passive vector I can think of right now is a dashboard widget or sidebar gadget (or whatever they call those things in Vista) running in the background.&lt;br&gt;&lt;br&gt;Didn't the original Mac hack require a user interaction - going to a website?  Else it would have been a truly remote exploit.  Or has the exploit progressed / gotten nastier?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hash</dc:creator><pubDate>Wed, 25 Apr 2007 21:15:47 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322426</link><description>I really think you should be careful about assuming that user interaction is required to trigger this attack. There's a zillion ways to get malicious web content in front of a user, and most of them don't require people to click on links.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 17:08:04 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322425</link><description>IE7 in protected mode.&lt;br&gt;&lt;br&gt;I know this same issue was brought up in previous threads, but even with IE7 in protected mode in Vista, if the exploit could use say a "Pop Up" to invoke the IEInstal.exe (admin broker) process and the user authenticated it via allow/don't allow, wouldn't it be "game over" as Thomas often like to say? &lt;br&gt;&lt;br&gt;On OSX, an install dialog box would require admin password, on Vista wouldn't it be a spoofed and/or a real UAC dialog box?  Not that it makes any difference, but I am thinking of the mindset when the exploit is rendered using click to a web site.&lt;br&gt;&lt;br&gt;If you "clicked" to go to the website hosting the exploit.  Wouldn't you click on the allow button if the Website politely asked for access?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hash</dc:creator><pubDate>Wed, 25 Apr 2007 16:24:52 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322424</link><description>@mmiller&lt;br&gt;the flaw in QuickTime + Java, not Javascript.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">carl</dc:creator><pubDate>Wed, 25 Apr 2007 14:57:47 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322423</link><description>I just have a simple question that I'm sure some one can answer.  If you visit this apple website.&lt;br&gt;&lt;br&gt;&lt;a href="http://developer.apple.com/documentation/QuickTime/Conceptual/QTScripting_JavaScript/index.html" rel="nofollow"&gt;http://developer.apple.com/documentation/QuickT...&lt;/a&gt;&lt;br&gt;&lt;br&gt;Read the information in the gray box.&lt;br&gt;&lt;br&gt;“Starting with QuickTime 7.1.5, you can no longer issue javascript:// URLs or call Javascript functions from within QuickTime movie.  This feature was removed from Quicktime for security reasons.”.&lt;br&gt;&lt;br&gt;The date at the bottom of that page is 3/26/2007.  I don't know when QuickTime 7.1.5 was released.   If  Quicktime 7.1.5 was installed on the system when Shane Macaulay used the exploit from Dino Dai Zovi. Should that Javascript exploit worked at all?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mmiller</dc:creator><pubDate>Wed, 25 Apr 2007 14:18:37 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322422</link><description>Firefox is also vulnerable</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">luc</dc:creator><pubDate>Wed, 25 Apr 2007 13:28:25 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322421</link><description>"Bad Apple"&lt;br&gt;&lt;br&gt;ROFL.&lt;br&gt;&lt;br&gt;Thanks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hash</dc:creator><pubDate>Wed, 25 Apr 2007 13:26:38 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322420</link><description>"this": no offense, but 3Com has now confirmed (twice more) that this vulnerability affects both IE6 and IE7 on WinXPSP2. I'm enjoying reading discussions about sandboxing/protection technologies in IE, so, by all means continue --- however, I'm going to delete comments that assert, by some semantic argument about "sandboxing", that this vulnerability isn't present on IE.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 12:59:13 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322419</link><description>Matasano is the name of our company. We chose it from a list of names of "exotic" (for Northeasterners) fruits and vegetables. It happens to sort of mean "bad apple", which we also like.&lt;br&gt;&lt;br&gt;Our friend Ivan Arce from CORE informed us shortly after we chose the name that it also means "quack doctor" in South America. "Killer of the healthy". So we like the name even more now.&lt;br&gt;&lt;br&gt;"Chargen" comes from the name of my previous personal blog. It's a service you can connect to on old Unix boxes to get a stream of gibberish, which you can use to test your ability to read gibberish from random hosts. It seemed like an apt metaphor for blogging.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 12:52:57 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322418</link><description>First I wanted to commend y'all for a great site / blog.  Very informative, and I'm glad to get past the religious OS flame wars. I have been lurking for a while and have a stupid newbie question.&lt;br&gt;&lt;br&gt;What does Matasano Chargen mean?  Where did that name come from?  &lt;br&gt;&lt;br&gt;I looked at the about pages, wiki, faq, etc. and couldn't find the answer.  I know I am a geek and stupid stuff like this bothers me.&lt;br&gt;&lt;br&gt;Then again, they say the only stupid Q is the one not asked.&lt;br&gt;&lt;br&gt;Thanks,&lt;br&gt;&lt;br&gt;Hash</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hash</dc:creator><pubDate>Wed, 25 Apr 2007 12:50:27 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322417</link><description>@Rosyna&lt;br&gt;In IE6 and IE7 the Plug-ins run in a sandbox.&lt;br&gt;sandbox is the memory location where the code is running, it's NOT the IE7's protected mode</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">this</dc:creator><pubDate>Wed, 25 Apr 2007 11:50:21 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322416</link><description>Thomas: As others have pointed out, DEP is by default turned off for IE.  You can override this by removing the opt-in/opt-out option and setting the appropriate boot.ini/bcdsettings to force DEP to always on.  Unless you have a good reason to not do this, I would recommend doing so anyway (forcing NX support enabled with the boot parameter), as it is possible (though convoluted) to disable NX on-the-fly for the current process, from the context of certain exploit scenarios with a ret2libc style attack[1].&lt;br&gt;&lt;br&gt;Rosyna: The reason why UAC and Protected Mode appear to be interconnected is that they are both based on the token integrity level mechanism.  To put it simply, token integrity levels are a sort of additional type of kernel-supported access control (checked before conventional ACEs in an ACL), where objects with a security descriptor can be marked as requiring a certain minimum integrity level to perform certain operations (e.g. read, write, execute).&lt;br&gt;&lt;br&gt;Barring any implementation bugs, the system does provide some limited real value, even if it somewhat of a hack.  How it works in protected mode is that your IE process runs with a "low" integrity level (the defaults for everything being "medium").  By default, all securable objects contain an ACL that denies write to low integrity callers (except for a couple of specially reserved locations under the userprofile tree, such as %userprofile%\AppData\LocalLow).  There are similar restrictions against writing to HKCU or HKLM; in practice, the default configuration locks out low integrity processes from writing outside of the HKCU\Software\AppDataLow key.&lt;br&gt;&lt;br&gt;In essence, integrity levels are a sort of bolt-on addition to the NT security model that allows you to partition a user into different trust levels, with lower trust level instances of a user (e.g. low integrity) being prevented from stomping on higher trust level instances of the same user.&lt;br&gt;&lt;br&gt;Now, this system isn't perfect.  You'll note, for instance, that I said that by default low integrity processes can't *write* to but a few restricted locations; they can still *read* (in the default configuration) from any location that the ACL would allow the user SID to access.  This means, for example, that a compromised IE protected mode process could still be used to, say, steal your top secret personal documents, if they were created under the same user and used the default security descriptor.  A compromised IE protected mode process could *not* be used to do things like overwrite those documents, though, or to drop code in locations where it might be run automagically (since there are only a handful of directories a low integrity process can write to by default, after which the process would have to convince the user to go out of his or her way to run a program dropped in such a location).  Because these restrictions are enforced by the kernel, they are ostensibly maintainable as secure (again, barring implementation bugs or design oversights).&lt;br&gt;&lt;br&gt;[1] &lt;a href="http://www.uninformed.org/?v=2&amp;amp;a=4&amp;amp;t=sumry" rel="nofollow"&gt;http://www.uninformed.org/?v=2&amp;amp;a=4&amp;amp;t=sumry&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Skywing</dc:creator><pubDate>Wed, 25 Apr 2007 11:25:08 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322415</link><description>You are all correct: &lt;br&gt;Initial testing of Dino's POC showed IE versions *not* to be vulnerable. &lt;br&gt;&lt;br&gt;After some slight modifications to the code, we were able to get the code working for IE6 and IE7 on XP. &lt;br&gt;We are still testing on Vista at this time. &lt;br&gt;&lt;br&gt;This is just what happens when the news coverage is faster than the investigation itself- more details unfold themselves over the course of a few days, and through further testing new things are learned.&lt;br&gt;&lt;br&gt;Remember, last Friday this was a vulnerability in Safari? ;-)&lt;br&gt;&lt;br&gt;We'll do our best to keep you folks updated here if anything changes regarding the details of the vulnerability itself.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Terri Forslof</dc:creator><pubDate>Wed, 25 Apr 2007 11:01:37 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322414</link><description>"Sandbox is the java sandbox implemented in Internet Explorer 6 and 7."&lt;br&gt;&lt;br&gt;I can't seem to understand this statement. Neither IE6 nor IE7 ship with a JVM. So a Java sandbox couldn't be implemented *in* them. IE7 implements Protected Mode on Vista (if UAC is on, which is the default). Everyone but Microsoft would refer to what Protected Mode implements as a "sandbox". Perhaps MS went with a different term due to the association the word "sandbox" has with urine and hidden fecal matter.&lt;br&gt;&lt;br&gt;Sun explicitly refers to Protected Mode as a "sandbox" in their release notes &lt;a href="http://java.sun.com/javase/6/webnotes/#windowsvista" rel="nofollow"&gt;http://java.sun.com/javase/6/webnotes/#windowsv...&lt;/a&gt; and they explicitly call out the fact an applet on XP can do whatever it wants.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rosyna</dc:creator><pubDate>Wed, 25 Apr 2007 10:48:09 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322413</link><description>Sandbox is the java sandbox implemented in Internet Explorer 6 and 7. It's not the protected mode!!!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">this</dc:creator><pubDate>Wed, 25 Apr 2007 10:09:08 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322412</link><description>"this", it's called Protected Mode...&lt;br&gt;&lt;br&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2007/04/04/protected-mode-for-ie7-in-windows-vista-is-it-on-or-off.aspx" rel="nofollow"&gt;http://blogs.msdn.com/ie/archive/2007/04/04/pro...&lt;/a&gt;&lt;br&gt;&lt;br&gt;And as I said, it's off if UAC is off and as I implied, it's for Vista only.&lt;br&gt;&lt;br&gt;Also, as I said, DEP is off in IE7 on XP and Vista by default. And from the comments, it seems that DEP doesn't play well with Java. How amusing given the current problem.&lt;br&gt;&lt;br&gt;&lt;a href="http://blogs.msdn.com/michael_howard/archive/2006/12/12/update-on-internet-explorer-7-dep-and-adobe-software.aspx" rel="nofollow"&gt;http://blogs.msdn.com/michael_howard/archive/20...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rosyna</dc:creator><pubDate>Wed, 25 Apr 2007 09:31:54 -0000</pubDate></item><item><title>Re: BREAKING: The Bug Report That Would Not Die: Dino&amp;#8217;s Finding Works In IE7</title><link>http://www.matasano.com/log/839/the-bug-report-that-would-not-die-dinos-finding-works-in-ie7/#comment-2322411</link><description>Also, IE6 doesn't have a "sandbox" feature.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 09:06:04 -0000</pubDate></item></channel></rss>