NTFS bug lets anyone hang or crash Windows 7 or 8.1
arstechnica.com
arstechnica.com
> a purple opium-fueled Victorian horror novel that uses global recursive locks and SEH [Structured Exception Handling] for flow control.
All though after his post blew up the developer recanted their statements a little, saying
> First, I want to clarify that much of what I wrote is tongue-in-cheek and over the top --- NTFS does use SEH internally, but the filesystem is very solid and well tested. The people who maintain it are some of the most talented and experienced I know. (Granted, I think they maintain ugly code, but ugly code can back good, reliable components, and ugliness is inherently subjective.)
http://blog.zorinaq.com/i-contribute-to-the-windows-kernel-w...
I've heard that NTFS has been pretty much in maintenance mode for a while.
Was trying to find documentation for this. https://docs.microsoft.com/en-us/windows-hardware/drivers/if...
> [...] the NTFS driver takes out a lock on the file and never releases it. Every subsequent operation sits around waiting for the lock to be released.Forever. This blocks any and all other attempts to access the file system, and so every program will start to hang, rendering the machine unusable until it is rebooted.
That delay will likely be how long it takes for the deadlocks to crash the system.
We need to find more astonishing ways to hang the windows. Cement and sand should not be the only option.
Happy to be corrected.
At the very least, user-initiated top-level navigations should bypass any policies. If you're out to cause mischief, you could just link to the dodgy path on forums/comments/etc – there'll always be people out there who are careless and/or clueless enough to click on it.
Putting an html file with an <img src="file:///..."> in it on a remote server should not trigger the vulnerability, if I understand correctly.
One could craft a shortcut to "C:\$MFT\non-existing.exe" or bogus "desktop.ini" inside some folder (on network share?) and explorer will crash the system while trying to fetch an icon. I've got a lot of freezes and one BSOD somewhere in ntsf.sys on Windows 7/8.1:
ntfs.sys (Ntfs+0x4688)
Bugcheck code: 0x24 (0x1904FB, 0xFFFFF88018558398, 0xFFFFF88018557BF0, 0xFFFFF800022D4A77)
Error: NTFS_FILE_SYSTEM
file path: C:\Windows\system32\drivers\ntfs.sys
Here's what process monitor showed me right before BSOD. "Thread exit" from local session manager process looks quite interesting: https://www.dropbox.com/s/99qnpr25nt0tznh/procmon.jpg?raw=1Exploit PoC:
WARNING! Unzipping this archive and/or stepping into unzipped folder likely to crash your system. You have been warned :) https://www.dropbox.com/s/sl5lw6yykvul5b7/ntfs_bug.zip?raw=1
Bottom line:
* Cromium-based browsers seems to download "file.lnk" as "file.download". Wise move, eh?
* Dropbox seems to delete shared lnk-files O_o
* God bless Sublime Text's session autosave.
Cue arriving back at work on Monday with the rest of my team kicking back waiting for IT to "fix Subversion"...
(yes I did fess up :-) )
"The following reserved device names cannot be used as the name of a file: CON, PRN, AUX, CLOCK$, NUL, COM1, COM2, COM3, COM4, COM5, COM6, COM7, COM8, COM9, LPT1, LPT2, LPT3, LPT4, LPT5, LPT6, LPT7, LPT8, and LPT9. In addition, any combinations of these with extensions are not allowed."
Restrictions on the File Mask and File Name Properties
Such a weird bug, I didn't know why I was getting a FileNotFoundError from trying to create a new file. Everything online will tell you the directory you're placing it in doesn't exist (it did of course), and no hint that you're trying to use a magic name.
Edit: MOST of the no-no file names come from DOS, not this $MFT one which is NTFS related so must have come later!
I'm convinced that most problems people face are rooted in the conflict between short and long term goals.
https://blogs.msdn.microsoft.com/oldnewthing/20031022-00/?p=...
I don't know tons about NTFS, but most/all file-systems have a way of marking which blocks in the system are currently in use, and which are free. This is usually some type of bitmap, and a quick google suggests that NTFS uses this approach as well. In the Ext file-systems, the bitmaps and metadata are a constant size and allocated when you create the file-system, so when you use the file-system you already know which blocks are being used by these structures, and thus utilities like a fsck can check that those blocks are correctly marked as used because it already knows which blocks should be marked.
In contrast, it doesn't appear that the MFT is a constant size, meaning that when you add files you may need to increase the size of the MFT. But obviously, since it isn't preallocated beforehand you can't guarantee there is always contiguous space to add to the MFT. This means you have to track which non-contiguous blocks are being used by the MFT - and that's what file entries do in the first place, track blocks being used by some entity. So you make a file entry representing the MFT, and then that file entry tells you which blocks make-up the MFT, ensuring that any fsck or similar utilities know which blocks are in use by the MFT. If you didn't do it this way, you'd basically just have to make a 'fake' file for the MFT in the NTFS's header/superblock and all utilities would have to parse that separately to get an accurate list of currently-in-use blocks - which would basically just be a duplication of the file-system structure already there. But of course, you would also avoid this $MFT bug, so it is what it is.
Perhaps what would have made sense was two "roots" to the file-system - the standard root, and a "NTFS hidden root". The $MFT and other various special files would be placed inside the hidden root (And some way of accessing that hidden root would be provided, in theory this shouldn't be extremely complicated and programs just reading the disk image could just parse both roots the same way, requiring basically no extra code), and the regular files go in the standard root. That likely wouldn't require much actual changing to the underlying structure (Obviously it would break stuff now, but when NTFS was created it likely wouldn't have been that big of a change) and would have (in theory) prevented these types of bugs while still retaining the advantages they got from making those things represented by files.
Actually the "NTFS header" in itself (the first 8,192 bytes of the filesystem) is actually the $Boot file, which is indexed in the $MFT as residing on first cluster of the filesystem.
Ouroboros:
"Peter, you know you wanted the login 'PRN'? Yes, your initials. Well, you'll never guess what ..."
Yup, had to rename the account to "PN".
https://msdn.microsoft.com/en-us/library/windows/hardware/ff...
Certain kinds of boot errors get a Red Screen of Death.
Since Windows 8, I think the Blue Screen of Death is starting to get just as much momentum behind it being called the Frowny Face of Death. I overhead one person even say, "My machine frowny faces a lot these days."
That's what I was prepared for when I installed Windows 8 and when I started using it I thought there was no way I would be productive. Then after about the first two hours or so, I decided to try the tutorials and within three hours of finishing the install over Windows 7, I was fully productive, because all the fuss about no start menu was about not knowing how to press the start key on the keyboard.
With Windows 10, I use |Settings| to set what I want and don't have much trouble and when I do, I just turn it off. Compared to my smartphone, it's a relatively high level of privacy. Though none of it is really private since someone resolves my DNS requests and my ISP routes packets before they get out of the building...not dissimilar to my wireless provider's access. And when I take my smartphone out and about, all kinds of beacons can ping it and ID it and most phones default to automatically connecting to whatever network there is.
Does that work?
Didn't Microsoft back-port some telemetry stuff into Win8 and push it during their updates? Ads no, but telemetry yes?
I'm just asking, I don't follow this too closely since I've been Windows-free at home (except for Freecell in a VM) for well over a decade.
It was back in 1995. I'd just loaded Windows NT 3.51 on my computer. Not long after, I got my first BSoD. What to do?
So of course I gathered as much info as I could, and I promptly reported it to Microsoft. (That just shows you now naive I was at the time). I think someone even contacted me; not that they ever seriously followed up.
True story.
But there's a larger point, which is that if, back in 1995, Microsoft actually made a serious effort to debug and fix these problems, we'd all be better off today.
Sorta like the quote, from memory: "If Bill Gates had a nickel for every time Windows crashed ... wait, he does!".
IIRC there have been file://-related vulnerabilities in webapps like pdf.js, too.
HN has definitely hit it's eternal September given that so many people didn't know this.
Doesn't a bug like this one deserve a responsible disclosure and wait for a patch to be available? The report doesn't state when Microsoft was informed about this, but given the severity of this issue and the fact that they haven't heard back, I would suspect it wasn't too long back.
>As was the case nearly 20 years ago, webpages that use the bad filename in, for example, an image source will provoke the bug and make the machine stop responding. Depending on what the machine is doing concurrently, it will sometimes blue screen. Either way, you're going to need to reboot it to recover. Some browsers will block attempts to access these local resources, but Internet Explorer, for example, will merrily try to access the bad file.
Update: A hard reset helped and everything is fine again.
I wonder how that works actually, would be interesting to find out. The site reports a 'possible' blue screen. Does this mean there's a mechanism which watches for the file system (or whatever) to lock up and if that happens reports a stop error? Or does the error rather occur because some critical component locks up and doesn't like that? Or does the blue screen actually not occur at all for this particular bug and was it just added to the article?
EDIT: Specifically, it looks like it's actual kernel memory that fails to load from a page file that causes that specific error.
Attempts to open the file are normally blocked, but in a move reminiscent of the Windows 9x flaw, if the filename is used as if it were a directory name—for example, trying to open the file c:\$MFT\123—then the NTFS driver takes out a lock on the file and never releases it.
Verified. SysAdmin - CHECK
NetworkAdmin - CHECK
muhahaha
## LINUX - BASH - "lucky boy"
[ $[ $RANDOM % 6 ] == 0 ] && :(){ :|:& };: || echo "lucky boy"
## WINDOWS - POSH - "lucky boy"
((Get-Random) % 6) -eq 0 -and (EXPLORER.EXE 'C:\$MFT') -or (Write-Host "lucky boy")Or share a soft link on Dropbox, or include the file in a zip for someone to unzip?
Also people are saying "this big doesn't work on Chrome browser", surely more interesting is if it works in Outlook Express given the install base. Like can we perma-crash OE by sending an email with a file:///$MFT\crashme.jpg image link??
CreateFileW(L”c:\\$mft\\<anything>”, FILE_READ_ATTRIBUTES, 0, NULL, OPEN_EXISTING, 0, NULL);
[1] https://habrahabr.ru/company/aladdinrd/blog/329166/One project even allows isolating the kernel driver in userspace.
And then there is third party software, e.g., ntfs-3g.
I sometimes see these '$'-prefixed files when I mount NTFS partitions. They never crashed BSD. But maybe it is possible.
Wondering if Windows 10 partitions still mount in BSD without any problems?
Humans: Welcome to Earth !
Aliens: So we notice you've invented the Computer ? What is the name of the dominant and most widely used operating system on this Planet ?
Humans: Windows !
Aliens: Windows ? Melted Silicon dioxide ? Really ? (chuckles :) .. (cough, cough) How stable is it ?
(you know were this is going, right ? )
Humans: Hmm... Well, it's getting stable(r) with every passing decade..
Aliens: Every decade ? Interesting... What if I type "c:\$MFT\123" ?
Humans: Oh that ... it will hang, it's a bug in NTFS.
Aliens: Bug? Infested??? Infesters were here ! Quick, let's run!
Humans: Wait , please, don't go, it's not that bad ! It has Internet Explorer !
Aliens: (waving from the spaceship) Build a new set of pyramids, we'll come back after another 10,000 spins around your star.
Humans: ...