On mySimon: Hoover Porta Power Vaccum
BNET Business Network:
BNET
TechRepublic
ZDNet

December 10th, 2008

IE7 XML parsing zero day exploited in the wild

Posted by Dancho Danchev @ 5:57 pm

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Exploit code, Hackers, Malware, Microsoft, Patch Watch, Windows Vista, Zero-day attacks

Tags: Security, Internet Explorer 7, XML, Windows XP, Windows Vista, Dancho Danchev

MS Internet Explorer XML Parsing Remote Buffer OverflowA couple of hours ago, two working proof of concept exploits for MS Internet Explorer XML Parsing Remote Buffer Overflow were posted at Milw0rm, with international hacking communities quickly catching up and starting to use it. The second PoC also works on Vista, in particular both exploits were tested on Vista SP1, Explorer 7.0.6001.18000, Vista SP0 Explorer 7.0.6000.16386, and also on WinXP SP3, Explorer 7.0.5730.13.

And if that’s not enough, Microsoft is also investigating a second zero day affecting the WordPad text converter according to an advisory issued yesterday.

Not surprisingly, the IE7 exploit is already in circulation, with the Shadowserver Foundation keeping track of malicious domains using it, the majority of which still remain active. Despite the fact the in its current form the exploit code is easy to spot through generic detection for potentially malicious shellcode, sampling several of the domains using it reveals that the Chinese hackers using it are also taking advantage of several different client-side vulnerabilities in order to increase the chances of successful infection. Typical exploits structure looks like the following :

baidu .bbtu01. cn/c0x.htm
baidu. bbtu01. cn/ie07.htm
baidu. bbtu01. cn/104.htm
baidu. bbtu01. cn/a0s.htm
baidu. bbtu01. cn/c0e.htm
baidu. bbtu01. cn/lzz.htm
baidu. bbt
u01. cn/Bf0yy.htm
baidu. bbtu01. cn/rea0l10.htm
baidu. b
btu01. cn/real11.htm

Despite that the malicious domains remain injected at legitimate Chinese sites and forums as iFrames only, this could easily change so that more legitimate international sites start getting targeted. What are they after this time? Passwords for popular online games in China.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 9 Talkback(s)
Don't mind....
Loverock. He misses alot of things because he is in love with Bill Gates. (Read the rest)
Posted by: todbran@... Posted on: 12/12/08 You are currently: a Guest | | Terms of Use
Thank goodness for Protected Mode  PB_z | 12/10/08
Let's Cut to the Chase  DannyO_0x98 | 12/11/08
Protected Mode does not prevent code from running.  ye | 12/11/08
Just About to Move On  DannyO_0x98 | 12/12/08
yet another reason to keep the UAC enabled  qmlscycrajg | 12/10/08
I think i'll take the paranoid approach..  JT82 | 12/11/08
RE: IE7 XML parsing zero day exploited in the wild  Loverock Davidson | 12/11/08
Did you miss this sentence?  msalzberg | 12/11/08
Don't mind....  todbran@... | 12/12/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here