cpjitservices Posted July 20, 2011 Posted July 20, 2011 (edited) Hey Guys, As I found out today there is a huge gaping hole in Server 2008 R2, MS have been informed about this hole on the 8th of this month- as yet they haven't released an update. SO disable your RDP ! Edited July 20, 2011 by plexer sensitive
kmount Posted July 20, 2011 Posted July 20, 2011 Did your colleague discover + report this or has it been publicised on the net? I ask because if it's not been publicised I'd probably not want to make as much info available as you have incase it provides enough info for someone to exploit it in the wild. If it's been publicised already then fair enough.
kmount Posted July 20, 2011 Posted July 20, 2011 ah, seen a mod has already edited it. Ignore my last post
mavhc Posted July 20, 2011 Posted July 20, 2011 If we don't have the info how can we properly secure it? noone's going to disable rdp just because of some guy on a forum
cpjitservices Posted July 20, 2011 Author Posted July 20, 2011 lol I was only being sarcastic anyway about disabling RDp - just thought I'd let you all know about my findings, as for MS knowing all I know is it was submited to them on the 8th.
localzuk Posted July 21, 2011 Posted July 21, 2011 right, soooo. what? Indeed. As it stands, what we get from this thread is that there is a threat to RDP on 2008 R2, but that we don't need to turn RDP off as you were joking. So, on a scale of 1-10, with 10 being 'oh my god, our servers are going to go on a rampage eating children' and 1 being 'nothing to see here', we are at around 2...
kmount Posted July 21, 2011 Posted July 21, 2011 Trusted colleagues feel free to PM me if you want the gist of what it said before it was edited.
cpjitservices Posted July 21, 2011 Author Posted July 21, 2011 Hi Guys, sorry for being vague been VERY Busy, I dont know much about the hole to be honest but it was a serious issue for me considering my Admin accounts got disabled, I can't go into to much detail but it was done from RDP, PM me if you want to know more.
cpjitservices Posted July 27, 2011 Author Posted July 27, 2011 Hi guys, a little more information which I found out today - the hole is in the Ease of Access feature at the logon screen, my colleague can manage to get the command prompt up from the ease of access, not usre how but he can and from there he can run mmc and then well all you need to do is add/remove snapins and viola!! your in!!! 1
strawberry Posted July 27, 2011 Posted July 27, 2011 One of our kids found that weeks ago, luckily he owned up
mrbios Posted July 30, 2011 Posted July 30, 2011 So if perchance someone had replaced the ease of access file within system32 with a fake one that just pops up and says "ease of access has been disabled by your administrator" this security hole isn't a problem? If that's the case i should be ok EDIT: can i have a PM with the details to test?
Arthur Posted July 31, 2011 Posted July 31, 2011 The Ease of Access button can be made non-functional by using the following registry key... Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe] "Debugger"="%SystemRoot%\\System32\\Calc.exe" Calc.exe will not run at the logon screen, so nothing happens when the button is clicked. 1
Arthur Posted July 31, 2011 Posted July 31, 2011 (edited) They're essentially the same OS, so yes. Edited July 31, 2011 by Arthur
eddyc Posted July 31, 2011 Posted July 31, 2011 There is some more information on this, plus a demo of the hole here; Windows security hole gives anyone access to computer without logging into User Account | The Windows Club
Steve21 Posted July 31, 2011 Posted July 31, 2011 There is some more information on this, plus a demo of the hole here; Windows security hole gives anyone access to computer without logging into User Account | The Windows Club My issue with that, Is it means the user needs to actually "change" the system. They're replacing the ease of access exe with a new exe. Which they shouldn't have access to do in the first place? And even once they do that, they'd only have access to local files, aka roaming profiles etc wouldn't be accessible. "imo" it's similar to saying install a keylogger and they can log in... Well yeah, but they shouldn't be able to? (Unless I missed something) Steve
Arthur Posted July 31, 2011 Posted July 31, 2011 My issue with that, Is it means the user needs to actually "change" the system. They're replacing the ease of access exe with a new exe. Which they shouldn't have access to do in the first place? ^^ Exactly! I agree with the response Microsoft gave in that article. It's extremely easy to replace any file with a malicious one once you have physical access. If this is the same "hole" which @cpjitservices is talking about, I would rate it 1 out of 10 on @localzuk's scale.
Steve21 Posted July 31, 2011 Posted July 31, 2011 cpjitservices[/mention] is talking about' date=' I would rate it 1 out of 10 on [mention=1433']localzuk[/mention]'s scale. There are some easy ways to access it, if you have access to it (but not sure about RDP) for example, using PE boot CD gives instant access to cmd. Run few "rename/copy" commands, and there you have access to any program through ease of access again. But again, need access to the machine at least Steve
jamesfed Posted July 31, 2011 Posted July 31, 2011 There are some easy ways to access it, if you have access to it (but not sure about RDP) for example, using PE boot CD gives instant access to cmd. Run few "rename/copy" commands, and there you have access to any program through ease of access again. But again, need access to the machine at least Steve Bitlocker helps out with this - not that every machine has a TPM chip in though......
jamesb Posted August 2, 2011 Posted August 2, 2011 Bitlocker helps out with this - not that every machine has a TPM chip in though...... A USB key's always an option.
jamesfed Posted August 2, 2011 Posted August 2, 2011 A USB key's always an option. Certinly be - we've got SD cards in all our staff laptops that don't have TPM. 1
FN-GM Posted August 2, 2011 Posted August 2, 2011 Certinly be - we've got SD cards in all our staff laptops that don't have TPM. Good idea didnt think of that!
happymeal Posted August 2, 2011 Posted August 2, 2011 So, on a scale of 1-10, with 10 being 'oh my god, our servers are going to go on a rampage eating children' and 1 being 'nothing to see here' Hmmm - just noticed it's oddly quiet here, and my server has gone walkies. Hang on, who could that be knocking on my door...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now