Vulnerability Development mailing list archives

Re: icq 2000 ads


From: Aussie <vuln-dev () securityfocus com>
Date: Thu, 22 Feb 2001 19:50:23 +1100

On 21 Feb 01, at 14:54, Blue Boar wrote:

If anyone does any exploration on how an attacker can trigger
the auto-update themselves, that will be on-topic, and I'd
like to see that.

(Hopefully on-topic)

  Has anyone checked the actual data received from
http://cb.icq.com/cb/431/datafiles/regupdat.cb ??
  There appears to be the possibility of forging/hacking/spoofing the domain
and generating a custom cb file. The data I received has a registry key
included in it, one that *may* be capable of being changed to anything (
HKCU/Software/Windows/CurrentVersion/Run sound likely?) and therefore a
virus/trojan/worm etc could be downloaded or run at next bootup.

[part of the .cb file I just retrieved]
<root>
        <item>
                <version>431</version>
                <from>430</from>
                <to>431</to>
                <key>Software\Mirabilis\ICQ\DefaultPrefs\</key>
                <item>MOTDTime</item>
                <deletekey>false</deletekey>
                <type>2</type>
                <value>t</value>
                <binary>
                        <param>
                                <_type>integer</_type>
                                <val>30</val>
                        </param>
                </binary>
        </item>
.....

  Allowing any program to automatically update the registry from an online
script is not my idea of security. Possibly this is an area that should be
inspected and checked to ensure Mirabilis has locked in limits to the registry
keys they permit their .cb files to alter.
  My firewall detected access to this URL even though I have specifically
requested that ICQ not attempt to update itself through both configuration and
registry. I have now locked this domain out while I have ICQ running and after
a few minutes, ICQ stops trying to connect and force an update I have no wish
to do.

Aussie


PGP Key Block available at:
http://aussie.mine.nu/aussie/pgp_key.txt


Current thread: