New Worm targets BlackICE vulnerability

  • Thread starter Thread starter Axel Pettinger
  • Start date Start date
Gabriele Neukam said:
On that special day, Axel Pettinger, ([email protected]) said...


Overwrites the first 64k of the defective dll, or of the hard disk?

My guess is that it grabs nearby data in RAM to write to disk
(defective dll) It makes an API call and uses the return data in
some sort of algorthm to "ramdomize" its choosing of which
sector to write to. It is a "version dependency" because the
API call it uses in the randomizer routine yields no return in
some version(s) of a DLL and the randomizer always causes
the first sector to be the result. Like a call to a 'tick count' that
in some version(s) is not supported so each time the call is
made the retun is the same (either an error code or a 'nothing'
each time.
 
What are you talking about here? Sure, any program can write to an NTFS
protected system based on the security context of the account being used at
the time of the compromise.

But only through the file system, not to raw disk. IOW, you can't
dump over file system structures or boot code, only the files you open
to write to. And NTFS is supposed to add value to that my mediating
further when it comes to which files you are allowed to open.

OTOH, as described, Witty writes directly to arbitrary sectors. Even
Win9x DOS mode doesn't allow that (Lock required first).
You're going to need to come-up with some proof here with some
*hard* evidence showing that something can be written to a NTFS
protected system if the account being used at the time doesn't have
write permission to back up your statements.

If Witty trashes NTFS file systems by writing to arbitrary sector
addresses, even when these are parts of NTFS's code structure, then
that is the proof required. If OTOH Witty mearely opens arbitrary
files and writes garbage inside, that would be different - and I'd
expect it would have been described differently.

It's meningless to talk file and user permissions if you have raw
access to overwrite arbitrary sectors.


-------------------- ----- ---- --- -- - - - -
Running Windows-based av to kill active malware is like striking
a match to see if what you are standing in is water or petrol.
 
But only through the file system, not to raw disk. IOW, you can't
dump over file system structures or boot code, only the files you open
to write to. And NTFS is supposed to add value to that my mediating
further when it comes to which files you are allowed to open.

OTOH, as described, Witty writes directly to arbitrary sectors. Even
Win9x DOS mode doesn't allow that (Lock required first).


If Witty trashes NTFS file systems by writing to arbitrary sector
addresses, even when these are parts of NTFS's code structure, then
that is the proof required. If OTOH Witty mearely opens arbitrary
files and writes garbage inside, that would be different - and I'd
expect it would have been described differently.

It's meningless to talk file and user permissions if you have raw
access to overwrite arbitrary sectors.

It would be nice to see some article on this before I'll completely buy
into it. But OTOH, I cannot dispute what you're saying either. :)

Duane :)
 
Back
Top