evolve or die

NRVA05-03.txt

NRVA05-03.txt
Posted Jul 28, 2005
Authored by Park Gyutae

HAURI live update suffers from remote file download and execution vulnerabilities.

tags | advisory, remote, vulnerability
MD5 | b0c582692ccecdb7dab8e7a8d192f5e0

NRVA05-03.txt

Change Mirror Download
--0-1750842756-1122367970=:45124
Content-Type: text/plain; charset=euc-kr
Content-Transfer-Encoding: 8bit

Dear F/D Mailling
-----------[Cut Cut]--------------------------------
Title: HAURI live update. Arbitrary remote file download and execute vulnerability
Discoverer: Original discoverer Neo
Original exploit improver PARK, GYU TAE (saintlinu@null2root.org)
Advisory No.: NRVA05-03
Critical: High Critical
Impact: Arbitrary file download from Internet and executable
Where: From remote
Operating System: Windows Only
Solution: Patched
Affected S/W: http://update.nprotect.net/newlivecall/engine/livecall.cab#version=2004,6,25,1 by Neo
http://fx.HAURI.net/HProduct/livesuite/XXXXXXX/CLIENT/LiveSuite/web/HLiveRobotWeb.cab#version=2005,6,21,1 by Saintlinu
Notice: 06. 29. 2005 initiated
06. 30. 2005 2ND No response
07. 05. 2005 Vendor responded and will be patched until 07. 22. 2005
07. 21. 2005 patched
07. 26. 2005 Disclosure vulnerability
Description:
HAURI is an anti virus vendor in Korea
The livesuite offers services to users scanning and treating virus, worm, hack tools and so on from Internet
See following detail describe:
[The first half]
Neo discovered vulnerability at http://update.nprotect.net/newlivecall/livecall.html
HAURI never check parameters When updates from Internet update server
also HAURI never check file's checksum or hash value.
He modified liveup.haz file, it's live update configuration file
that file just compressed by ZIP compressor.
if HAURI user access phishing page such as can use BBS that has vulnerability such as cross site script
then evil software downloaded without any restrict
evil software like cmd.exe if exist then HAURI overwrites.
[The latter half]
As you seen above. Saintlinu improved Neo's exploit.
Saintlinu found HAURI LIVE UPDATE program at XXX Commercial companies in Korea
HAURI checked files in liveup.haz but that's all.
File's checksum is date and time when it made
therefore we can exploit that vulnerability.
Technical Describe:
NOT INCLUDED HERE
-----------[Cut Cut]--------------------------------
I higher respect Neo
Special thanks for My best group Null@root.
PS. I'm very sorry for poor my konglish


---------------------------------
¹«·á 1GB¿ë·®!, ´õÀÌ»ó ¿ë·® °í¹Î¾ø´Â ¾ßÈÄ! ¸ÞÀÏÀ» ½áº¸¼¼¿ä. ´ëÇѹα¹ ºí·Î±×°¡ ¸ðÀÎ °÷!
ÇÇÇøµ¿¡¼­ ³×À̹ö, À̱۷罺¸¦ ¸¸³ª´Ù ¾ßÈÄ! ¸ð¹ÙÀÏ
ÃֽŠÈÞ´ëÆù Á¤º¸, º§¼Ò¸®, ij¸¯ÅÍ, ¹®ÀÚ¸Þ¼¼Áö
--0-1750842756-1122367970=:45124
Content-Type: text/html; charset=euc-kr
Content-Transfer-Encoding: 8bit

<DIV>Dear F/D Mailling</DIV>
<DIV>-----------[Cut Cut]--------------------------------</DIV>
<DIV>Title:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; HAURI live update. Arbitrary remote file download and execute vulnerability</DIV>
<DIV>Discoverer:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Original discoverer Neo<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Original exploit improver PARK, GYU TAE (<A href="mailto:saintlinu@null2root.org">saintlinu@null2root.org</A>)</DIV>
<DIV>Advisory No.:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NRVA05-03</DIV>
<DIV>Critical:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; High Critical</DIV>
<DIV>Impact:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Arbitrary file download from Internet and executable</DIV>
<DIV>Where:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; From remote</DIV>
<DIV>Operating System:&nbsp; Windows Only</DIV>
<DIV>Solution:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Patched</DIV>
<DIV>Affected S/W:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <A href="http://update.nprotect.net/newlivecall/engine/livecall.cab#version=2004,6,25,1">http://update.nprotect.net/newlivecall/engine/livecall.cab#version=2004,6,25,1</A> by Neo<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <A href="http://fx.HAURI.net/HProduct/livesuite/XXXXXXX/CLIENT/LiveSuite/web/HLiveRobotWeb.cab#version=2005,6,21,1">http://fx.HAURI.net/HProduct/livesuite/XXXXXXX/CLIENT/LiveSuite/web/HLiveRobotWeb.cab#version=2005,6,21,1</A> by Saintlinu</DIV>
<DIV>Notice:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 06. 29. 2005 initiated<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 06. 30. 2005 2ND No response<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 07. 05. 2005 Vendor responded and will be patched until 07. 22. 2005<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 07. 21. 2005 patched <BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 07. 26. 2005 Disclosure vulnerability </DIV>
<DIV>Description: </DIV>
<DIV>HAURI is an anti virus vendor in Korea</DIV>
<DIV>The livesuite offers services to users scanning and treating virus, worm, hack tools and so on from Internet</DIV>
<DIV>See following detail describe:</DIV>
<DIV>[The first half]</DIV>
<DIV>Neo discovered vulnerability at <A href="http://update.nprotect.net/newlivecall/livecall.html">http://update.nprotect.net/newlivecall/livecall.html</A><BR>HAURI never check parameters When updates from Internet update server<BR>also HAURI never check file's checksum or hash value.</DIV>
<DIV>He modified liveup.haz file, it's live update configuration file<BR>that file just compressed by ZIP compressor.</DIV>
<DIV>if HAURI user access phishing page such as can use BBS that has vulnerability such as cross site script <BR>then evil software downloaded without any restrict</DIV>
<DIV>evil software like cmd.exe if exist then HAURI overwrites.</DIV>
<DIV>[The latter half]</DIV>
<DIV>As you seen above. Saintlinu improved Neo's exploit. </DIV>
<DIV>Saintlinu found HAURI LIVE UPDATE program at XXX Commercial companies in Korea</DIV>
<DIV>HAURI checked files in liveup.haz but that's all.<BR>File's checksum is date and time when it made</DIV>
<DIV>therefore we can exploit that vulnerability. </DIV>
<DIV>Technical Describe:</DIV>
<DIV>NOT INCLUDED HERE</DIV>
<DIV>-----------[Cut Cut]--------------------------------</DIV>
<DIV>I higher respect Neo</DIV>
<DIV>Special thanks for My best group <A href="mailto:Null@root">Null@root</A>.</DIV>
<DIV>PS. I'm very sorry for poor my konglish</DIV><p>
<hr size=1>
<style type='text/css'>
<!--
a.ftag:link {text-decoration:none; color:2A47AA}
a.ftag:visited {text-decoration:none; color:2A47AA}
a.ftag:hover {text-decoration:underline; color:2A47AA}
a.ftag:active {text-decoration:none; color:2A47AA}
.ftag {font-family:±¼¸²,µ¸¿ò,arial; font-size: 80%; line-height: 140%; font-size:9pt; color:#666666}
-->
</style>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td style="padding:10 0 0 0" class=ftag>
<img src="http://img.yahoo.co.kr/mail/footer/ic_mail.gif" width="21" height="11"> ¹«·á 1GB¿ë·®!, ´õÀÌ»ó ¿ë·® °í¹Î¾ø´Â <b><a href="http://mail.yahoo.co.kr" class=ftag>¾ßÈÄ! ¸ÞÀÏ</a></b>À» ½áº¸¼¼¿ä.
</td>
</tr>
<tr>
<td width="50%" height="5">
</td>
</tr>
</table>
<table width="617" border="0" cellspacing="0" cellpadding="0">
<tr>
<td style="border-left:1px solid #CCCCCC;border-right:1px solid #CCCCCC;border-top:1px solid #CCCCCC;border-bottom:1px solid #CCCCCC;padding:8 8 8 8">
<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="42" valign="top">
<a href="http://us.rd.yahoo.com/mail_kr/taglines/mobile/*http://kr.ring.yahoo.com"><img src="http://img.yahoo.co.kr/ring/event/peoplering_footer.gif" width="32" height="32" border="0"></a>
</td>
<td valign="top" class=ftag>
<b><a href="http://us.rd.yahoo.com/mail_kr/taglines/mobile/*http://kr.ring.yahoo.com" class=ftag>´ëÇѹα¹ ºí·Î±×°¡ ¸ðÀÎ °÷!</a></b><br>
ÇÇÇøµ¿¡¼­ ³×À̹ö, À̱۷罺¸¦ ¸¸³ª´Ù
</td>
</tr>
</table>
</td>
<td width="10"></td>
<td width="1" background="http://img.yahoo.co.kr/mail/footer/bg_dot01.gif"></td>
<td width="10"></td>
<td>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="42" valign="top">
<a href="http://us.rd.yahoo.com/mail_kr/taglines/peoplering/*http://kr.mobile.yahoo.com" class=ftag><img src="http://img.yahoo.co.kr/mail/footer/ic_mobile.gif" width="32" height="32" border="0"></a>
</td>
<td valign="top" class=ftag>
<b><a href="http://us.rd.yahoo.com/mail_kr/taglines/peoplering/*http://kr.mobile.yahoo.com" class=ftag>¾ßÈÄ! ¸ð¹ÙÀÏ</a></b><br>
ÃֽŠÈÞ´ëÆù Á¤º¸, º§¼Ò¸®, ij¸¯ÅÍ, ¹®ÀÚ¸Þ¼¼Áö
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
<img src='http://kr.recptproxy.mail.yahoo.com/updaterc?mid=47r3ozEsbZ_Fauyrs8xnp6A--&extra=0' width=0 height=0>
--0-1750842756-1122367970=:45124--

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close