<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Attack of the URL Vulnerabilities</title>
	<atom:link href="http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37116</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 26 Jul 2007 06:43:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37116</guid>
		<description>Jordan, thanks for the good research. yes, it is very interesting. Have you taken snapshots of the registry tree for each setup? because now we can detect what&#039;s the cause of it. I have some very wild guess but it is good to have some proof. cheers</description>
		<content:encoded><![CDATA[<p>Jordan, thanks for the good research. yes, it is very interesting. Have you taken snapshots of the registry tree for each setup? because now we can detect what&#8217;s the cause of it. I have some very wild guess but it is good to have some proof. cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37087</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Thu, 26 Jul 2007 02:31:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37087</guid>
		<description>Looks like I&#039;m not the only person to observe that:

https://bugzilla.mozilla.org/show_bug.cgi?id=389580#c6</description>
		<content:encoded><![CDATA[<p>Looks like I&#8217;m not the only person to observe that:</p>
<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=389580#c6" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=389580#c6</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37074</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Thu, 26 Jul 2007 01:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37074</guid>
		<description>pdp -- I realize that, but there&#039;s something else going on.  Check this out to see what I mean:

XPSP2 with no patches + Firefox = Exploit fails
XPSP2 with all patches (sans IE7) + Firefox = Exploit fails
XPSP2 with all patches (including IE7) + Firefox = Exploit succeeds!
XPSP2 with no patches + Firefox + Thunderbird installed and configured = Exploit fails
XPSP2 with no patches except for IE7 + Firefox + Thunderbird = Exploit succeeds!

I&#039;ve tried other combinations besides those, and the only way I can get the exploit to succeed is if IE7 is installed.  If anyone&#039;s able to get the exploit working without IE7 installed, I&#039;d be really curious to know.</description>
		<content:encoded><![CDATA[<p>pdp &#8212; I realize that, but there&#8217;s something else going on.  Check this out to see what I mean:</p>
<p>XPSP2 with no patches + Firefox = Exploit fails<br />
XPSP2 with all patches (sans IE7) + Firefox = Exploit fails<br />
XPSP2 with all patches (including IE7) + Firefox = Exploit succeeds!<br />
XPSP2 with no patches + Firefox + Thunderbird installed and configured = Exploit fails<br />
XPSP2 with no patches except for IE7 + Firefox + Thunderbird = Exploit succeeds!</p>
<p>I&#8217;ve tried other combinations besides those, and the only way I can get the exploit to succeed is if IE7 is installed.  If anyone&#8217;s able to get the exploit working without IE7 installed, I&#8217;d be really curious to know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37048</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 25 Jul 2007 20:38:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37048</guid>
		<description>Jordan, again, it depends on the URL handler for the &lt;strong&gt;mailto:&lt;/strong&gt; protocol.

Adrian, yes, yes and yes.</description>
		<content:encoded><![CDATA[<p>Jordan, again, it depends on the URL handler for the <strong>mailto:</strong> protocol.</p>
<p>Adrian, yes, yes and yes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37040</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Wed, 25 Jul 2007 19:28:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37040</guid>
		<description>It&#039;s very worrying how easy it is to exploit this vulnerability and how well it works.

I must research these URI handler bugs!</description>
		<content:encoded><![CDATA[<p>It&#8217;s very worrying how easy it is to exploit this vulnerability and how well it works.</p>
<p>I must research these URI handler bugs!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37038</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Wed, 25 Jul 2007 19:26:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37038</guid>
		<description>Ok, just ran it a second time after reverting the snapshot, and sure enough -- a base SP2 machine is /not/ vulnerable for some reason.  Got the regmon logs, but I don&#039;t have the time to parse through them right now.  

Here&#039;s a zip with a screenshot showing the exploit fail, regmon logs of the exploit both failing and then succeeding on the same machine just with and without patches:

http://www.psifertex.com/download/firefox-command-injection.zip

Maybe someone else can figure it out while I get back to pretending to work on this other project here at my office.  ;-)</description>
		<content:encoded><![CDATA[<p>Ok, just ran it a second time after reverting the snapshot, and sure enough &#8212; a base SP2 machine is /not/ vulnerable for some reason.  Got the regmon logs, but I don&#8217;t have the time to parse through them right now.  </p>
<p>Here&#8217;s a zip with a screenshot showing the exploit fail, regmon logs of the exploit both failing and then succeeding on the same machine just with and without patches:</p>
<p><a href="http://www.psifertex.com/download/firefox-command-injection.zip" rel="nofollow">http://www.psifertex.com/downl.....ection.zip</a></p>
<p>Maybe someone else can figure it out while I get back to pretending to work on this other project here at my office.  ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37036</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Wed, 25 Jul 2007 19:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37036</guid>
		<description>pdp -- there&#039;s something else involved in the process that&#039;s disrupting it.

I just grabbed all the updates for the SP2 machine, and /now/ the exploit works.  Outlook Express is still registered as the mailto handler just like it was before I grabbed the updates.  

So in short, install a standard SP2 machine.  Exploit fails.  Install latest security patches.  Exploit succeeds.  

Lemme verify it again and use regmon to trace the registry calls to see if I can find out what&#039;s different.</description>
		<content:encoded><![CDATA[<p>pdp &#8212; there&#8217;s something else involved in the process that&#8217;s disrupting it.</p>
<p>I just grabbed all the updates for the SP2 machine, and /now/ the exploit works.  Outlook Express is still registered as the mailto handler just like it was before I grabbed the updates.  </p>
<p>So in short, install a standard SP2 machine.  Exploit fails.  Install latest security patches.  Exploit succeeds.  </p>
<p>Lemme verify it again and use regmon to trace the registry calls to see if I can find out what&#8217;s different.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37032</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 25 Jul 2007 18:48:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37032</guid>
		<description>Jordan, the vector does not work if you have Outlook as a default &lt;strong&gt;mailto:&lt;/strong&gt; handler. If your default Mail client is Thunderbird, then you shouldn&#039;t have any problem with launching the attack. BTW, try using other protocols. It works like a charm.</description>
		<content:encoded><![CDATA[<p>Jordan, the vector does not work if you have Outlook as a default <strong>mailto:</strong> handler. If your default Mail client is Thunderbird, then you shouldn&#8217;t have any problem with launching the attack. BTW, try using other protocols. It works like a charm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37031</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Wed, 25 Jul 2007 18:39:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37031</guid>
		<description>Odd -- I&#039;ve been trying to test this in a base XP image, with no luck.  Does it really require SP2 to work?  That&#039;d be kind of ironic.  Outlook Express is the default registered mail handler for mailto: on the test system I just installed into vmware.  I&#039;m going through the upgrades now, testing it at each step to see at what point it becomes vulnerable.</description>
		<content:encoded><![CDATA[<p>Odd &#8212; I&#8217;ve been trying to test this in a base XP image, with no luck.  Does it really require SP2 to work?  That&#8217;d be kind of ironic.  Outlook Express is the default registered mail handler for mailto: on the test system I just installed into vmware.  I&#8217;m going through the upgrades now, testing it at each step to see at what point it becomes vulnerable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larholm.com - Me, myself and I &#187; Handling URL protocol handlers</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-37024</link>
		<dc:creator>Larholm.com - Me, myself and I &#187; Handling URL protocol handlers</dc:creator>
		<pubDate>Wed, 25 Jul 2007 18:01:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-37024</guid>
		<description>[...] Jesper Johanson has expressed his thoughts, as has David LeBlanc, Billy Rios, Window Snyder and pdp. Billy Rios just detailed yet another potential attack vector for protocol [...]</description>
		<content:encoded><![CDATA[<p>[...] Jesper Johanson has expressed his thoughts, as has David LeBlanc, Billy Rios, Window Snyder and pdp. Billy Rios just detailed yet another potential attack vector for protocol [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-36997</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 25 Jul 2007 13:08:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-36997</guid>
		<description>good, cuz I am not saying anything either :)</description>
		<content:encoded><![CDATA[<p>good, cuz I am not saying anything either :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities/comment-page-1/#comment-36996</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Wed, 25 Jul 2007 13:07:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/attack-of-the-url-vulnerabilities#comment-36996</guid>
		<description>I&#039;m won&#039;t say anything ;)
http://noscript.net/changelog#1.1.6.07</description>
		<content:encoded><![CDATA[<p>I&#8217;m won&#8217;t say anything ;)<br />
<a href="http://noscript.net/changelog#1.1.6.07" rel="nofollow">http://noscript.net/changelog#1.1.6.07</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
