ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Black Hat Sneak Preview

By | August 1, 2008, 12:46am PDT

Summary: Rob McMillan from IDG interviewed John Heasman and I today about the presentation we will be delivering with Rob Carter at Black Hat Vegas next week. The article has a good teaser about one of the more interesting of the many attacks we will cover, namely what we’ve coined the GIFAR attack. We’ve [...]

Rob McMillan from IDG interviewed John Heasman and I today about the presentation we will be delivering with Rob Carter at Black Hat Vegas next week. The article has a good teaser about one of the more interesting of the many attacks we will cover, namely what we’ve coined the GIFAR attack. We’ve also got a previous teaser that I covered here on some of John Heasman’s work on NTLM relay attacks through Java applets.

For those who are not familiar with this, we originally discussed it during the Black Hat webcast. The attack involves combining two files, for instance a GIF image file and a JAR (Java Archive) file that contains class files for a Java Applet. GIF+JAR=GIFAR. The idea is that the file will be rendered as a valid image by a browser; however, it will also be treated as a valid JAR file for use as a Java Applet by the Java Virtual Machine.

There are numerous web applications out there that allow you to upload images, but very few that allow you to upload Java class files. This is for the obvious reason that an attacker created applet uploaded onto a legitimate web application will allow the execution of arbitrary applet code in the victim’s browser under the context of the web application it was loaded from. Of course, this all goes out the door if you can convince the application that what you have is a valid file for its purposes, yet still deliver the Java applet to the server.

I want to avoid giving up too many details prior to Black Hat, but I would like to clarify some points from Rob’s article and comment on some other relevant points to our talk:

  1. GIFARs are not the only thing we are talking about during our presentation. The focus of our talk is to demonstrate a feasible compromise of an organization via client-side attacks that require no code execution and that even work against IE running in protected mode. This is an interesting topic as protections like DEP and ASLR have made client-side compromise of an organization tougher as the classic memory corruption flaws are tougher to exploit (tips my hat to Alex Sotirov and Mark Dowd and their Black Hat talk on the subject).
  2. The GIFAR issue will not be patched at the time of the conference; however, a few of the required steps to exploit the issue will be held back until Sun has issued a patch that will protect users from this in the short term.
  3. The issue exploits applications that take ownership of user supplied content. Billy Rios and I originally presented similar attacks at DEFCON last year, showing how GMail, Yahoo!, etc. would accept a crossdomain.xml file as an attachment, and then using that fact to bypass Same Origin Policy using Adobe Flash.
  4. Billy Rios is actually the original founder of the GIFAR vulnerability. Rob credited me in his article (my fault for not clarifying), but I was only part of the research, Billy deserves the real credit for the find.
  5. There was a comment in the article about this being really a browser security issue. That plays into some of our research, but most of our research has little to do with browser-security issues and more to do with issues in the web applications themselves, or in third-party browser plugins.
  6. While the GIFAR issue may appear to be a Sun flaw on the surface, it is not. The fact that the JVM will load an applet from an image file is certainly not a great thing, but the real issue here is an application level issue, and that is web applications are accepting uploads of things like images without validating those uploads (save for checking their extension).
  7. Sun has been great to work with and has been kind enough to work on a patch for the issue, which we hope to see out soon. The patch will provide a temporary work around for this issue, which will give application owners time to address this within their applications. It does not fix the issue of applications taking ownership of user supplied content without better sanitizing of the content. Loading a Java applet through an image file is just the vector of exploitation we used here, the issue really being that the applications allowed us to place this content on the web server in a predictable location.
  8. The GIFAR issue is likely to effect any web application that accepts uploads of content from users without sanitizing this data beyond checking the file extension and file headers. GIFARs can be files other than combined GIF+JAR files, they could also be JPG+JAR, DOC+JAR, etc.
  9. Our presentation features Billy Rios, Rob Carter, John Heasman, and myself and covers all of our recent work on client-side exploitation, and it should be fun.

Hope to see some of you there, but I will not fault you if you miss us, as there are a couple of other great talks at that time as well, including Jeremiah Grossman and Mark Dowd with Alex Sotirov. In any case, if you are going to be there, feel free to come chat with Rios, Carter, Heasman, and I. We will be up for beer, coffee, lunch, and/or gambling.

-Nate

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Disclosure

Nathan McFeters

http://i.zdnet.com/images/auth/nmcfeters_53x53.jpg

Biography

Nathan McFeters

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
12
Comments

Join the conversation!

Just In

RE: Black Hat Sneak Preview
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
0 Votes
+ -
RE: Black Hat Sneak Preview
xiaodou 26th Sep
chanel replica bags
0 Votes
+ -
RE: Black Hat Sneak Preview
xiaodou 26th Sep
replica hermes bags
0 Votes
+ -
RE: Black Hat Sneak Preview
MACKENZI 11th Sep
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
0 Votes
+ -
RE: Black Hat Sneak Preview
lovedong 13th Sep
Win! Thank you!! replica hermes bags
0 Votes
+ -
RE: Black Hat Sneak Preview
PEARLINEI 12th Sep
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
0 Votes
+ -
RE: Black Hat Sneak Preview
RHIANNONA 13th Sep
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
0 Votes
+ -
RE: Black Hat Sneak Preview
SATURNINA 14th Sep
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
0 Votes
+ -
RE: Black Hat Sneak Preview
TOCCAR 25th Sep
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
0 Votes
+ -
RE: Black Hat Sneak Preview
MCKNIGH 26th Sep
Thanks nice info z d n e t I really liked your current article write more..let me add you to its favorite The articles you have on zdnet s i t e are always so enjoyable to read. Good work and I bookmarked it.
0 Votes
+ -
RE: Black Hat Sneak Preview
MEJIAHA 30th Sep
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
0 Votes
+ -
RE: Black Hat Sneak Preview
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix