Windows 'shortcut' attack code goes public
One researcher publishes exploit, another touts defense for Microsoft's newest zero-day
Computerworld - A security researcher on Sunday published a working exploit of a critical Windows vulnerability, making it more likely that attacks will spread.
According to a security advisory issued Friday by Microsoft, hackers can use a malicious shortcut file, identified by the ".lnk" extension, to automatically run their malware simply by getting a user to view the contents of a folder containing the shortcut. Malware can also automatically execute on some systems when a USB drive is plugged into the PC.
All versions of Windows, including the just-released beta of Windows 7 Service Pack 1 (SP1), as well as the recently retired Windows XP SP2 and Windows 2000, contain the bug.
Sunday, a researcher known as "Ivanlef0u" published proof-of-concept code to several locations on the Internet. Later that day, Belgian researcher Didier Stevens -- who in late March revealed a serious design flaw in Adobe's PDF document format -- confirmed that Ivanlef0u's code could be tweaked to create an effective attack.
Stevens also announced that he'd tested Ivanlef0u's exploit against a tool he'd written a year ago, and said that the utility successfully blocked attacks launched from USB flash drives and CDs. "You can use Ariad if you want to mitigate attacks with these shortcut links until Microsoft releases a patch," Stevens said of the tool in a Sunday blog.
In the blog post, Stevens illustrated how to set up Ariad to block executable files, including .lnk files, from running from a USB or CD drive. He also urged users to read Ariad's online documentation, and warned them that running it could be risky. "Ariad is a mini-filter drive, and as such operates inside the Windows kernel," Stevens said. "Bugs in kernel software can have grave consequences: the dreaded BSOD [Blue Screen of Death]. So please test this software first on a test machine you can miss."
Stevens clearly told rookie users to steer clear of the tool. "I don't want inexperienced users to install this. [Ariad] is not user-friendly," he said.
Microsoft's defensive advice thus far has been limited to recommending that users edit the Windows registry to disable the displaying of all shortcut icons, and to switch off the WebClient service.
Another researcher didn't think much of Microsoft's workarounds. "This is highly impractical for most environments," argued Chester Wisniewski, a senior security advisory with Sophos. "While it would certainly solve the problem, it would also cause mass confusion among many users and might not be worth the support calls," he said. "Microsoft also suggests disabling the WebClient service that is used for WebDav. If you are not a Microsoft SharePoint customer this may be a solution, but many organizations rely on SharePoint so this is limiting as well."
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts