Aurora and DEP in Windows
In January there was a big attack against Google that apparently used a flaw in Internet Explorer which got the name "aurora".
This has supposedly prompted Google to pull out of China so there are international business and political issues involved. I won't go into those details and will only focus on the technical aspects that will be seen by most people.
As of yet, the attackers have only targeted IE6 on XP in big corporations so some say that there is less of a threat if you are using IE7+ on Vista or later. There are two problems with that logic.
First of all, the exploit is in Megasploit (a clearing house for 0 day exploits) and it will soon be used against the mainstream. According to McAfee: “What started out as a sophisticated targeted attack is likely to lead to large-scale attacks on vulnerable Microsoft Internet Explorer users.”
Second of all the security researcher Dino Dai Zovi has written an Aurora exploit that works on IE 6 and IE 7 on XP and Vista. His exploit works in IE browsers that don't have DEP enabled. Even if that isn't enough; according to Microsoft's own security advisory (see below), the flaw includes IE7 and IE8 in everything up to Windows7. The flawed code that was exploited in IE6 exists in all browsers and all Microsoft OS's beyond 5.01 service pack 4. It was interesting to read Microsoft say that IE8 is vulnerable but IE5 isn't.
They will soon be issuing an "out of band patch" which they rarely do. Usually they wait until the third Tuesday of the month (patch Tuesday), but now they will be issuing an emergency update ASAP.
Microsoft has a list of what we can do to reduce the damage the exploit can do while they craft the patch.
- Turn on DEP (Data Execution Protection) in IE7
While DEP is turned on by default in IE8 on in XP service pack 3, Vista sp 1, and Windows7. In IE7
tools -> internet options -> advanced -> check "enable memory protection" - avoid browsing as an administrator
The way the exploit works it allows for scripts to run with your rights. If you are a limited user then the damage you can make to your computer is limited. This is a subject I've written about in other blogs so I wont go into it here. - set the internet security to high
These are the default security settings that that all web sites fall into if they aren't already in the Trusted or Restricted zone.
tools -> internet options -> security
click on the "internet" tab -> move the slide bar until 'high' is displayed - be sure protected mode is on in IE7
tools -> internet options -> security -> check "enable protected mode"
- Always off
It's kind of obvious what the problem is with this one. - Opt-In
Here you choose the programs that will be protected and the rest go unprotected. Basically it is a black list of bad programs. The black list approach is the scorn of security-land. But, of course, it is the default in Windows. I would recommend that you switch to one of the two below. - Always On
This seems to be the best bet although I would guess there are some programs out there that would stop working. Those programs were probably written without thought to security or the details but if the computer can do the job the user needs it to do then what good is it? So this setting would be best but maybe too much for most users. - Opt Out
Like the opt-in setting, in this setting the program decides if it must abide by the rules DEP sets down. Unlike the opt-in setting, you choose which programs will be allowed to run free and the rest will have to play by the rules.

Comments
AmThHsKDgeKpclicL
Glad I've finally found smotehing I agree with!
Post new comment