CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Securiteam notice of Kerio vulnerability

 
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
LoPhatPhuud

Security Expert
Microsoft MVP

Joined: Mar 09, 2002
Posts: 2229

MVP Phishing Squad Premium Security Experts

PostPosted: Sun Oct 01, 2006 8:13 pm    Post subject: Securiteam notice of Kerio vulnerability
Reply with quote

For full information see:
http://www.securiteam.com/windowsntfocus/6D0090AH5O.html

Original article posted here:
http://www.matousec.com/info/advisories/Kerio-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php


-----
Kerio Multiple Insufficient Argument Validation of Hooked SSDT Function Vulnerability

Hooking SSDT functions requires extra caution. SSDT function handlers are executed in the kernel mode but their callers are executed in the user mode. Hence all function arguments come from the user mode. This is why it is necessary to validate these arguments properly. Otherwise a simple user call can easily crash the whole system. This bug usually results in a system crash. However, it may happen that this bug is even more dangerous and can lead to the execution of an arbitrary code in the privileged kernel mode.

Sunbelt Kerio Personal Firewall hooks many functions in SSDT and in at least six cases it fails to validate arguments that come from user mode. User calls to NtCreateFile, NtDeleteFile, NtLoadDriver, NtMapViewOfSection, NtOpenFile, NtSetInformationFile with invalid argument values can cause system crashes because of errors in Kerio drivers fwdrv.sys and khips.sys. Further impacts of this bug (like arbitrary code execution in the kernel mode) were not examined.


Vulnerable software:
* Sunbelt Kerio Personal Firewall 4.3.268
* Sunbelt Kerio Personal Firewall 4.3.246
* Sunbelt Kerio Personal Firewall 4.2.3.912


_________________
Duct tape is like the Force. It has Light side and a Dark side and it holds the world together.

Microsoft MVP/Consumer Security 2005-2008
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
saz

Guest
IP: 87.3.*.*






PostPosted: Mon Oct 02, 2006 8:08 am    Post subject: Re: Securiteam notice of Kerio vulnerability
Reply with quote

oh my god! Shocked Crying or Very sad Crying or Very sad

Back to top
Dwarden

Private
Private


Joined: Oct 14, 2002
Posts: 39
Location: Czech_Republic

PostPosted: Mon Oct 02, 2006 3:25 pm    Post subject:
Reply with quote

why Sunbelt bought nearly 2 months ago security report about KPF and was not able fix these bugs in time ?

anyone from Sunbelt wanna comment some light on this ?

it seems that in end i'm waiting for security tests & reports about Outpost 4 to decide if scrap KPF completely ...

Back to top
View users profile Send private message
MarkB

Guest
IP: 80.229.*.*






PostPosted: Tue Oct 03, 2006 3:49 pm    Post subject:
Reply with quote

Dwarden wrote:

it seems that in end i'm waiting for security tests & reports about Outpost 4 to decide if scrap KPF completely ...


Or you can use Comodo which is now a mature program and passes all leak tests.

Mark

Back to top
earthsound

Trooper
Trooper


Joined: Mar 10, 2005
Posts: 21
Location: USA

PostPosted: Tue Oct 10, 2006 1:42 pm    Post subject:
Reply with quote

Just curious to see if Sunbelt has had any response to this problem and whether a beta was available to test a fix for this.

Here is the CVE-2006-5153 vulnerability summary:

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5153

david

Back to top
View users profile Send private message Visit posters website
pcguy999

Private
Private


Joined: Apr 19, 2005
Posts: 44
Location: USA

PostPosted: Sat Oct 14, 2006 3:39 pm    Post subject: Does Comodo push ads?
Reply with quote

Has anyone commented about this story that Comodo pushes ads down to users?

http://langa.com/newsletters/2006/2006-09-25.htm#5

Back to top
View users profile Send private message
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Sat Oct 14, 2006 4:39 pm    Post subject: Re: Does Comodo push ads?
Reply with quote

pcguy999 wrote:
Has anyone commented about this story that Comodo pushes ads down to users?

http://langa.com/newsletters/2006/2006-09-25.htm#5


Well, I've been using CF and CAVS for a while now and I've seen no such ads.

Smile

Back to top
View users profile Send private message
earthsound

Trooper
Trooper


Joined: Mar 10, 2005
Posts: 21
Location: USA

PostPosted: Mon Oct 16, 2006 3:05 pm    Post subject: Re: Does Comodo push ads?
Reply with quote

pcguy999 wrote:
Has anyone commented about this story that Comodo pushes ads down to users?

http://langa.com/newsletters/2006/2006-09-25.htm#5


By "ads" Alan means that Comodo can show you it's other free offerings within the Launch Pad application...which is sort of a central command app to control the various Comodo products you could have installed on your machine. And even in Launch Pad, you have to click in order to see what they offer. A screenshot is here:

http://forums.comodo.com/index.php/topic,173.msg1853.html#msg1853

The launchpad does not push ads to users via popups, nag screens, etc.

The worst thing he complained about the Launch Pad (and don't forget, this is 5 month old news) at the time was that there was "no documentation or mention of the add on software at Comodo’s web site. As well, there is no method to un-install the software without removing the desired application".

I haven't installed any Comodo software recently, so I cannot comment as to the validity of that statement in the current versions of Comodo software.

david[/b]

Back to top
View users profile Send private message Visit posters website
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Mon Oct 16, 2006 6:46 pm    Post subject: Re: Does Comodo push ads?
Reply with quote

I believe Comodo are going to do away with the Launch Pad once they release their AntiVirus. Shame, as I quite liked it Crying or Very sad.

Smile

Back to top
View users profile Send private message
J-Mac

Trooper
Trooper


Joined: Aug 13, 2006
Posts: 27
Location: USA

PostPosted: Wed Oct 18, 2006 3:46 am    Post subject:
Reply with quote

Just for the record, yes, Comodo does currently install the Launch Pad app without disclosure, and it is true that it cannot be removed without uninstalling the firewall.

At least it was true five weeks ago with the latest version of their firewall.

Other than being surprised that it was silently installed, I saw no particularly suspicious activity from it.

Back to top
View users profile Send private message Yahoo Messenger
LoPhatPhuud

Security Expert
Microsoft MVP

Joined: Mar 09, 2002
Posts: 2229

MVP Phishing Squad Premium Security Experts

PostPosted: Wed Oct 18, 2006 4:13 am    Post subject:
Reply with quote

J-Mac,

The latest version, 2.3.6.81, does not install LuanchPad.


_________________
Duct tape is like the Force. It has Light side and a Dark side and it holds the world together.

Microsoft MVP/Consumer Security 2005-2008
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer