Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Patch all those windows boxes

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Patch all those windows boxes
Reply
 
Thread Tools
Old 16-11-2014, 22:22   #1
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Patch all those windows boxes

Probably well known already but on Tuesday Microsoft released two patches among others that fix nasty holes in windows, all the way from windows 95 to windows 10. The SSL/TLS (schannel) bug is worse than the recent Heartbleed bug as it gives full remote command execution without any interaction. The OLE bug could potentially be used in drive-by exloits from visiting a url.

The patches have been reverse engineered and there is an unofficial metasploit module to exploit this but it's not 100% reliable yet. As the patches added some new ciphers too, a scanner looks for these new ssl options as a way to see if the box is patched. Not 100% foolproof either.

Home machines should already have the updates from windows update but servers may need some special love and attention. Patch details are in the CVE links.

Some news stories about these bugs:

http://www.bbc.co.uk/news/technology-30019976
http://www.theregister.co.uk/2014/11...rary_megaflaw/

CVE-2014-6321

Quote:
Overview
Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via crafted packets, aka "Microsoft Schannel Remote Code Execution Vulnerability."

Impact Subscore: 10.0
Exploitability Subscore: 10.0
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
CVE-2014-6332
Quote:
Overview
OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
Impact


Impact Subscore: 10.0
Exploitability Subscore: 8.6


Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type: Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
Qtx is offline   Reply With Quote
Advertisement
Old 17-11-2014, 10:29   #2
joglynne
Born again teenager.
 
joglynne's Avatar
 
Join Date: Feb 2007
Location: Manchester. (VM area 20)
Age: 77
Services: Maxit TV, M250 Fibre BB. Phone-Anytime Chatter
Posts: 13,883
joglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aura
joglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aura
Re: Patch all those windows boxen

I really must stop reading the threads in the Virus and Security Discussion area. They make me twitchy for the rest of the day as I wouldn't have a clue where to start dealing with the issues they raise.

Thanks for the information though as it's kind of reassuring that at least some of you on here know enough about all this to explain it to us less than savvy members.
__________________
"I intend to live forever, or die trying" - Groucho Marx..... "but whilst I do I shall do so disgracefully." Jo Glynne
joglynne is offline   Reply With Quote
Old 17-11-2014, 12:02   #3
Osem
Inactive
 
Join Date: Oct 2006
Location: Right here!
Posts: 22,315
Osem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered stars
Osem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered stars
Re: Patch all those windows boxen

Quote:
Originally Posted by joglynne View Post
I really must stop reading the threads in the Virus and Security Discussion area. They make me twitchy for the rest of the day as I wouldn't have a clue where to start dealing with the issues they raise.

Thanks for the information though as it's kind of reassuring that at least some of you on here know enough about all this to explain it to us less than savvy members.
Too true!!!

I'm hoping you'll be sending me your layman's interpretation of the OP shortly Jo...

This is the subject for another thread but should we really be rushing into a world in which our whole lives are 'stored' in the ether by one corporation/agency or another when there are all sorts of security issues evident for all to see and some to exploit?
Osem is offline   Reply With Quote
Old 17-11-2014, 12:04   #4
denphone
Still alive and fighting
 
denphone's Avatar
 
Join Date: Jun 2007
Location: In the land of beyond and beyond.
Services: XL BB, 3 360 boxes , XL TV.
Posts: 56,699
denphone has a golden auradenphone has a golden aura
denphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden auradenphone has a golden aura
Re: Patch all those windows boxen

l am a bit like Jo as l have no clue about these things but alas that's no surprise as l am a expert at nothing.
__________________
“The only lesson you can learn from history is that it repeats itself”
denphone is offline   Reply With Quote
Old 17-11-2014, 13:18   #5
joglynne
Born again teenager.
 
joglynne's Avatar
 
Join Date: Feb 2007
Location: Manchester. (VM area 20)
Age: 77
Services: Maxit TV, M250 Fibre BB. Phone-Anytime Chatter
Posts: 13,883
joglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aura
joglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aurajoglynne has a golden aura
Re: Patch all those windows boxen

Quote:
Originally Posted by Osem View Post
Too true!!!

I'm hoping you'll be sending me your layman's interpretation of the OP shortly Jo...

This is the subject for another thread but should we really be rushing into a world in which our whole lives are 'stored' in the ether by one corporation/agency or another when there are all sorts of security issues evident for all to see and some to exploit?
My take.

An broken Window is letting some potential baddies, in a car driving passed with a pair of long distance binoculars, look in to our little magic boxes to see what they can nick.
As a result some goodies have sent aound a glazier to fit obscured glass to try and block the baddie's view.

__________________
"I intend to live forever, or die trying" - Groucho Marx..... "but whilst I do I shall do so disgracefully." Jo Glynne
joglynne is offline   Reply With Quote
Old 17-11-2014, 14:48   #6
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Patch all those windows boxen

Windows update.

Reboot.

Simples.
qasdfdsaq is offline   Reply With Quote
Old 17-11-2014, 15:15   #7
Osem
Inactive
 
Join Date: Oct 2006
Location: Right here!
Posts: 22,315
Osem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered stars
Osem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered stars
Re: Patch all those windows boxen

Quote:
Originally Posted by denphone View Post
l am a bit like Jo as l have no clue about these things but alas that's no surprise as l am a expert at nothing.
Over 32,000 posts here suggests you're pretty damned good at something...

---------- Post added at 16:15 ---------- Previous post was at 16:14 ----------

So it's all sorted until the find the next one, or worse still, don't find the next one until it's too late...
Osem is offline   Reply With Quote
Old 17-11-2014, 16:09   #8
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Patch all those windows boxen

I'm starting to feel like it's time for a career change
qasdfdsaq is offline   Reply With Quote
Old 17-11-2014, 20:40   #9
Osem
Inactive
 
Join Date: Oct 2006
Location: Right here!
Posts: 22,315
Osem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered stars
Osem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered starsOsem is seeing silvered stars
Re: Patch all those windows boxen

Well if they make it all too safe, secure and layman-user friendly that's what might happen anyway...
Osem is offline   Reply With Quote
Old 18-11-2014, 23:44   #10
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: Patch all those windows boxen

Quote:
Originally Posted by qasdfdsaq View Post
Windows update.

Reboot.

Simples.
Not always that simple on a production domain controller and when the patch isn't on windows update. This new bug which lets any domain user become admin is a very nice privilege escalation goodie and is serious enough for MS to make an out-of-cycle patch quickly instead of waiting for the next patch date

Broken kerberos

Quote:
Vulnerability Details
CVE-2014-6324 allows remote elevation of privilege in domains running Windows domain controllers. An attacker with the credentials of any domain user can elevate their privileges to that of any other account on the domain (including domain administrator accounts).

The exploit found in-the-wild targeted a vulnerable code path in domain controllers running on Windows Server 2008R2 and below. Microsoft has determined that domain controllers running 2012 and above are vulnerable to a related attack, but it would be significantly more difficult to exploit. Non-domain controllers running all versions of Windows are receiving a “defense in depth” update but are not vulnerable to this issue.
http://blogs.technet.com/b/srd/archi...2014-6324.aspx

---------- Post added at 00:44 ---------- Previous post was at 00:39 ----------

Quote:
Originally Posted by joglynne View Post
I really must stop reading the threads in the Virus and Security Discussion area. They make me twitchy for the rest of the day as I wouldn't have a clue where to start dealing with the issues they raise.
Mostly info for system administrators, so leave the worrying to them You have a nice router giving you good protection via NAT (forget their mostly useless firewalls) so half of these problems can't get to you. So sleep well and forget all about the other half still left...
Qtx is offline   Reply With Quote
Old 19-11-2014, 12:57   #11
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Patch all those windows boxen

Quote:
Originally Posted by Qtx View Post
Not always that simple on a production domain controller and when the patch isn't on windows update. This new bug which lets any domain user become admin is a very nice privilege escalation goodie and is serious enough for MS to make an out-of-cycle patch quickly instead of waiting for the next patch date
Why would your production domain controller be used for hosting public websites and/or drive-by web browsing?
qasdfdsaq is offline   Reply With Quote
Old 19-11-2014, 13:43   #12
alanbjames
R.I.P.
 
Join Date: Jun 2012
Location: Swansea, South Wales UK.
Age: 74
Services: XL Phone, XXXL Gig1 BB SH4 (wired).
Posts: 2,753
alanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these partsalanbjames is just so famous around these parts
Re: Patch all those windows boxen

I used to drive by print at my mates. I would sit outside and print rude messages on his wireless printer and it would send him potty lol.
alanbjames is offline   Reply With Quote
Old 19-11-2014, 18:27   #13
Ignitionnet
Inactive
 
Join Date: Jun 2008
Location: Leeds, West Yorkshire
Age: 47
Posts: 13,995
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Re: Patch all those windows boxen

Quote:
Originally Posted by qasdfdsaq View Post
Why would your production domain controller be used for hosting public websites and/or drive-by web browsing?
I think the concern is more internal users escalating privileges and playing games as far as DCs go.

You'd hope nothing on the public Internet had Kerberos exposed.
Ignitionnet is offline   Reply With Quote
Old 20-11-2014, 10:47   #14
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Patch all those windows boxen

Ah, I was referring to the two CVE's listed in the OP. Yes the later KDC issue isn't quite as simple a fix but the Windows update => Reboot solution does still apply to the end user(s) scenario I was replying to.

That said Microsoft has been making more extensive use of Kerberos authentication for services that are often internet-accessible lately, including Remote Desktop, Direct Access, and so forth.
qasdfdsaq is offline   Reply With Quote
Old 20-11-2014, 23:02   #15
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: Patch all those windows boxes

Admins in some companies have to do change management requests and even testing of patches before they get applied to production servers. Certainly would not be done through windows updates for these servers.

Was talking about the new priv escalation in that particular post as Ignition pointed out. Internal users or even guest accounts for visitors with limited access being able to become admin and give themselves access to anything is a big issue, especially for organisations that want to keep their trade secrets secret.

OWA/the outlook web app is another thing that is often configured with kerberos.
Qtx is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 20:02.


Server: lithium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum