Microsoft: 0Day Exploit Targeting Word, Outlook
krebsonsecurity.com
krebsonsecurity.com
However, that might be bad practice.
Typical example of a buffer overflow that leads to execution specific to this case, although I'm sure this has been posted a million times here:
1. RTF parser allocates char[15] on the stack for storing the font family from {\fonttbl\...
2. Joe hacker shifts out a font definition of 15 chars plus a return address to some arbitrary code and the code itself.
3. The parser reads until the end of the fonttbl definition ;} which is longer than the buffer specified.
4. This blindly overwrites the return address by writing beyond the end of the buffer and pokes some arbitrary code on the end. If you're lucky this won't cause a bus error / MMU trap
5. The function returns and the malicious return address is jumped to executing Joe Hackers code.
Ultimately anyone can make this mistake when programming in C/C++ and they frequently do. It takes considerable skill to not blow your toes off like this.
There are certain mitigation method which prevent this but they aren't universally enabled or available or 100% effective.
I've pretty much given up on C these days but I spent a lot of time making sure stuff like this was impossible and most importantly avoided parsing anything myself when nice tools like lex/yaxx are around that have all this stuff safely wrapped up. I didn't win every time.
er yes.
Confirmed:
Content-Type: multipart/alternative;
boundary="_000_1B81DC42240AEE4B96F487A2683E7EEB0A6AE7505BTHHS2E12BE2Xh_"
MIME-Version: 1.0
--_000_1B81DC42240AEE4B96F487A2683E7EEB0A6AE7505BTHHS2E12BE2Xh_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
RTF test
From outlook 2013 in RTF mode...And I use mutt for my personal email...
I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_<
hopefully a fix comes in soon and I don't have to worry too much, I assume it will but getting everyone to update (well, forcing it) is a bit hard too.
"Monoculture" isn't always bad.
The odds of the attack being identified once that segment is compromised is much higher, since everyone else has the opportunity to identify the bad behavior.
So if you have 5 people using 5 different email clients, all 5 of those must be kept secure from spear phishing or email-viewing vulnerabilities to avoid having a hacker get a beachhead on your network.
But if those 5 people are using 1 email client, you only have to keep that 1 safe (and you'd have to keep it safe anyways).
Monocultures are probably bad for drive-by automated hacking though, so I suppose it's a matter of deciding what threat model you're most at risk from.
This argument may appeal to the self-indulgent system administrator who believes he alone knows perfection. In reality, there is no perfection. One must know there are things one does not know. If China is stock-piling zero days against Outlook, how are you to know? In fact, if there is anything we have learned from biological systems, surely it is that when a monoculture falls, it falls harder and faster than any other variation.
If you are trying to mitigate against all your computers being taken down at once, diversify. If you are trying to keep intruders out of your network, reduce your surface area.
You're right that no one is perfect, but that's no reason to expand the number of directions threats can come from.
If everyone uses different software, say for browsers, there are 3 or 4 major options and a fully reliable exploit (which is rare, but for the sake of argument) will still fail on 25% of targets. Now I need four 0days to know that I can compromise my target. If you're running multiple OSes, the same vulnerability requires a different exploit, so the number goes up even more. I also need a high quality rootkit that works on all of them.
It's not as though I only have to compromise a single box in an entire network to get what I need. Though I don't need to compromise every single box either, so in practice it's somewhere in the middle.
[1] http://en.wikipedia.org/wiki/Monoculture_%28computer_science...
The more options they use, the less likely it is the right person will be running the right exploitable client. You need all vulnerabilities aligned to succeed.
Now if you were discussing resistance to worms, everyone being different helps. It depends on your threat model.
1: https://technet.microsoft.com/en-us/security/advisory/295309...
There are true data analysis tools on the market, Excel is not one of them
However, it is the best tool for fast mockups and visualization.
probably you could instead spend those on writing an automated solution then run it against all machines?
http://blogs.technet.com/b/srd/archive/2014/03/24/security-a...