ALERT! Win 7 and vista users, re SMB

If your topic has nothing to do with Spyderco, you can post it here.
User avatar
vampyrewolf
Member
Posts: 7486
Joined: Fri Sep 24, 2004 10:33 am
Location: Saskatoon, Saskatchewan, Canada

ALERT! Win 7 and vista users, re SMB

#1

Post by vampyrewolf »

http://seclists.org/fulldisclosure/2009/Sep/0039.html
and a proof of concept on command line http://www.dereenigne.com/
http://hackaday.com/2009/09/09/windows- ... b-exploit/

Essentially puts it forward that if you have file sharing enabled you can recieve a BSoD.
SRV2.SYS fails to handle malformed SMB headers for the NEGOTIATE PROTOCOL REQUEST functionnality.
The NEGOTIATE PROTOCOL REQUEST is the first SMB query a client send to a SMB server, and it's used
to identify the SMB dialect that will be used for futher communication.
#!/usr/bin/python
# When SMB2.0 recieve a "&" char in the "Process Id High" SMB header field it dies with a
# PAGE_FAULT_IN_NONPAGED_AREA from socket import socket
Coffee before Conciousness
Why do people worry more if you argue with your voices than if you just talk with them? What about if you lose those arguements?
Slowly going crazy at work... they found a way to make the voices work too.
User avatar
tonydahose
Member
Posts: 6277
Joined: Thu Jan 19, 2006 7:56 am
Location: Chicago
Contact:

#2

Post by tonydahose »

what does that mean in English please :)
WTC #1444 Always Remember
Need info on a particular :spyder:, just click here
My knives
Spydie count: a few:D
User avatar
vampyrewolf
Member
Posts: 7486
Joined: Fri Sep 24, 2004 10:33 am
Location: Saskatoon, Saskatchewan, Canada

#3

Post by vampyrewolf »

from wiki:
In computer networking, Server Message Block (SMB) operates as an application-layer network protocol mainly used to provide shared access to files, printers, serial ports, and miscellaneous communications between nodes on a network. It also provides an authenticated Inter-process communication mechanism. Most usage of SMB involves computers running Microsoft Windows, where it is often known as "Microsoft Windows Network".
When discussing SMB, one should distinguish:

* the SMB protocol
* the SMB services that run on the protocol
* NetBIOS
* the DCE/RPC services that use SMB as an authenticated Inter-process communication channel (over named pipes)
* the "Network Neighborhood" protocols which primarily (but not exclusively) run as datagram services directly on the NetBIOS transport
pretty much means that an "invalid" request has the ability to kill your system if you have that port open (default is port 443 I believe). And that it's not hard to send an invalid request maliciously. Only affects systems with the driver installed, which means Win 7, Vista and Server 2008 (as far as I can find).
Best bet is to close the port until someone finds a fix for it.
Coffee before Conciousness
Why do people worry more if you argue with your voices than if you just talk with them? What about if you lose those arguements?
Slowly going crazy at work... they found a way to make the voices work too.
65535
Member
Posts: 15
Joined: Thu Aug 20, 2009 9:28 pm

#4

Post by 65535 »

Mac for the win.
User avatar
vampyrewolf
Member
Posts: 7486
Joined: Fri Sep 24, 2004 10:33 am
Location: Saskatoon, Saskatchewan, Canada

#5

Post by vampyrewolf »

xp pro and opensuse :p
Coffee before Conciousness
Why do people worry more if you argue with your voices than if you just talk with them? What about if you lose those arguements?
Slowly going crazy at work... they found a way to make the voices work too.
User avatar
psimonl
Member
Posts: 1948
Joined: Thu Jan 27, 2005 2:13 pm
Location: Montreal Qc Canada

#6

Post by psimonl »

Thanks for the infos, Vampyrewolf, but...

Some of your computer related thread are very hard to understand... :confused:

Simon
"Everyday above the ground and vertical is a good day".
-Sir A. Hopkins in "The world's Fastest Indian"

"If it hurts, it means you're not dead..."
-Kayakist Marie-Pier Cote

The Spyderco Cookbook
User avatar
vampyrewolf
Member
Posts: 7486
Joined: Fri Sep 24, 2004 10:33 am
Location: Saskatoon, Saskatchewan, Canada

#7

Post by vampyrewolf »

I confuse folks any time I talk to most people about computers :p

And then when I talk with IT folks few of em understand why I have a backup server with hardware that's 6-7 years old ;)
Coffee before Conciousness
Why do people worry more if you argue with your voices than if you just talk with them? What about if you lose those arguements?
Slowly going crazy at work... they found a way to make the voices work too.
User avatar
Kuolema
Member
Posts: 222
Joined: Fri Jun 26, 2009 4:10 pm
Location: Saskatoon, Saskatchewan, Canada

#8

Post by Kuolema »

Argh, another problem with my operating system.

All's I got to say is when I get my Win 7 Professional upgrade on my NetBook, this problem better be fixed. :mad:


Thanks for the heads up, though. I'm never ontop of these things and with me relying on my PC's and Laptops for University, you could have just saved my life. :p


Thanks again!
may it not be tricksy
User avatar
Tank
Member
Posts: 2085
Joined: Fri Sep 24, 2004 10:33 am
Location: N. Calif. USA

#9

Post by Tank »

vampyrewolf wrote: Best bet is to close the port until someone finds a fix for it.
I have vista, so how do I close this port?

Thanks
-John
User avatar
vampyrewolf
Member
Posts: 7486
Joined: Fri Sep 24, 2004 10:33 am
Location: Saskatoon, Saskatchewan, Canada

#10

Post by vampyrewolf »

Not sure where vista hides the firewall, I'd have to look it up.

SMB is on port 445, you'd just have to close that port on the firewall.
Coffee before Conciousness
Why do people worry more if you argue with your voices than if you just talk with them? What about if you lose those arguements?
Slowly going crazy at work... they found a way to make the voices work too.
User avatar
mikebandw186
Member
Posts: 272
Joined: Thu Nov 09, 2006 5:26 pm
Location: westminster, colorado

#11

Post by mikebandw186 »

psimonl wrote:Thanks for the infos, Vampyrewolf, but...

Some of your computer related thread are very hard to understand... :confused:

Simon
I get the same reaction when I say stuff like "Peel ply carbon fiber, S30V, micro serrations and a wire clip!"
“Open, close, cut, clean, oil, cut, cut, cut... To a Spyderco, that is living. Letting it die in the box is to lose 75% of what we put into it." Sal Glesser

Proudly carrying the SpyderEdge!

Chance is a fickle B$%^h and I have no faith in the judgmental abilities of criminals. -KaliGMan
User avatar
araneae
Member
Posts: 5506
Joined: Wed Aug 09, 2006 10:10 pm
Location: A lil more south of the Erie shore, Ohio

#12

Post by araneae »

Can I just use duct tape?
So many knives, so few pockets... :)
-Nick

Last in: N5 Magnacut
The "Spirit" of the design does not come through unless used. -Sal
User avatar
hickster
Member
Posts: 471
Joined: Sun Nov 16, 2008 9:04 pm
Location: AK

#13

Post by hickster »

65535 wrote:Mac for the win.
Rodger that! ;)
hickster
User avatar
The Deacon
Member
Posts: 25717
Joined: Fri Sep 24, 2004 10:33 am
Location: Upstate SC, USA
Contact:

#14

Post by The Deacon »

Question is, would this be an issue if your computer is configured so that file sharing is only allowed with computers within your trusted zone?
Paul
My Personal Website ---- Beginners Guide to Spyderco Collecting ---- Spydiewiki
Deplorable :p
WTC # 1458 - 1504 - 1508 - Never Forget, Never Forgive!
User avatar
vampyrewolf
Member
Posts: 7486
Joined: Fri Sep 24, 2004 10:33 am
Location: Saskatoon, Saskatchewan, Canada

#15

Post by vampyrewolf »

There is always the possibility of having a bad request come from internally, but blocking SMB external and forcing the use of FTP for external should take care of an extranl attack. And as far as internal users breaking it, thats why we keep backups, right?
Coffee before Conciousness
Why do people worry more if you argue with your voices than if you just talk with them? What about if you lose those arguements?
Slowly going crazy at work... they found a way to make the voices work too.
User avatar
m.and
Member
Posts: 40
Joined: Wed Jul 08, 2009 7:08 pm
Location: Virginia

#16

Post by m.and »

65535 wrote:Mac for the win.
+1. Love my Macs. :D
The journey of a thousand miles begins with one step - Lao Tzu
User avatar
The Deacon
Member
Posts: 25717
Joined: Fri Sep 24, 2004 10:33 am
Location: Upstate SC, USA
Contact:

#17

Post by The Deacon »

Ok, so if (BIG IF) I'm understanding this correctly, this is not really a security issue. By that I mean no real harm is done, no viruses, no file corruption, nothing phoning home with your banking details. Worst case, you machine locks up, but when you reboot, things are back to normal. Mine never was set up to allow file sharing, I still do transfers to and from my laptop the old fashioned way, sneaker net. :o :D

Truth be known, I'm quite happy overall with Vista. Aside from the single annoying habit of rebooting without warning to install updates, it's been rock steady for me since I got this machine.
Paul
My Personal Website ---- Beginners Guide to Spyderco Collecting ---- Spydiewiki
Deplorable :p
WTC # 1458 - 1504 - 1508 - Never Forget, Never Forgive!
User avatar
tonydahose
Member
Posts: 6277
Joined: Thu Jan 19, 2006 7:56 am
Location: Chicago
Contact:

#18

Post by tonydahose »

The Deacon wrote:
Truth be known, I'm quite happy overall with Vista. Aside from the single annoying habit of rebooting without warning to install updates, it's been rock steady for me since I got this machine.
i know i am going out on a really thin branch here but can't you change that in the settings of windows update? at least to pick which ones to install?
WTC #1444 Always Remember
Need info on a particular :spyder:, just click here
My knives
Spydie count: a few:D
User avatar
The Deacon
Member
Posts: 25717
Joined: Fri Sep 24, 2004 10:33 am
Location: Upstate SC, USA
Contact:

#19

Post by The Deacon »

tonydahose wrote:i know i am going out on a really thin branch here but can't you change that in the settings of windows update? at least to pick which ones to install?
Tony, your correct. More a mixture of procrastination and forgetfulness on my part. Every time it happened I swore I was going to fix it - later. :o Finally changed the settings. :D
Paul
My Personal Website ---- Beginners Guide to Spyderco Collecting ---- Spydiewiki
Deplorable :p
WTC # 1458 - 1504 - 1508 - Never Forget, Never Forgive!
User avatar
Tank
Member
Posts: 2085
Joined: Fri Sep 24, 2004 10:33 am
Location: N. Calif. USA

#20

Post by Tank »

any word if this issue has been resolved?
-John
Post Reply