<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hotpatching MS08-067</title>
	<atom:link href="http://www.nynaeve.net/index.php?feed=rss2&#038;p=226" rel="self" type="application/rss+xml" />
	<link>http://www.nynaeve.net/?p=226</link>
	<description>Adventures in Windows debugging and reverse engineering.</description>
	<lastBuildDate>Tue, 24 Aug 2010 12:05:39 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Yuhong Bao</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-57121</link>
		<dc:creator>Yuhong Bao</dc:creator>
		<pubDate>Tue, 09 Feb 2010 02:30:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-57121</guid>
		<description>.text:000007FF7738E5D6 mov     rcx, 0FFFFFFFFFFFFFFFFh
.text:000007FF7738E5E0 mov     rdi, r8
.text:000007FF7738E5E3 repne scasw

BTW, 65nm Core 2 has errata relating to executing REP SCAS/CMPS with values exceeding 0x100000000. Luckily, it is mentioned that Intel has a microcode update to fix this, which would be essential since it is code generated by a common compiler.</description>
		<content:encoded><![CDATA[<p>.text:000007FF7738E5D6 mov     rcx, 0FFFFFFFFFFFFFFFFh<br />
.text:000007FF7738E5E0 mov     rdi, r8<br />
.text:000007FF7738E5E3 repne scasw</p>
<p>BTW, 65nm Core 2 has errata relating to executing REP SCAS/CMPS with values exceeding 0&#215;100000000. Luckily, it is mentioned that Intel has a microcode update to fix this, which would be essential since it is code generated by a common compiler.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microsoft Releasing Out-of-Band Security Patch &#171; ThreatFire Research Blog</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-51098</link>
		<dc:creator>Microsoft Releasing Out-of-Band Security Patch &#171; ThreatFire Research Blog</dc:creator>
		<pubDate>Tue, 27 Oct 2009 21:24:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-51098</guid>
		<description>[...] in mind that the update requires a reboot.For all you hardcore hax0rs, Skywing has put together a detailed post on using the AT service and hiew to to inject the updated code into svchost.exe and manually hot [...]</description>
		<content:encoded><![CDATA[<p>[...] in mind that the update requires a reboot.For all you hardcore hax0rs, Skywing has put together a detailed post on using the AT service and hiew to to inject the updated code into svchost.exe and manually hot [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wireless hack,Wifi hack &#38; security &#187; Blog Archive &#187; Microsoft Hotpatching MS08-067</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-38832</link>
		<dc:creator>Wireless hack,Wifi hack &#38; security &#187; Blog Archive &#187; Microsoft Hotpatching MS08-067</dc:creator>
		<pubDate>Sun, 05 Jul 2009 10:41:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-38832</guid>
		<description>[...] reverse engineering most present-day Microsoft security patches is not particularly insurmountable.  In detail  Posted in Security &#124;     Leave a [...]</description>
		<content:encoded><![CDATA[<p>[...] reverse engineering most present-day Microsoft security patches is not particularly insurmountable.  In detail  Posted in Security |     Leave a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Conficker/Downadup worm strikes &#124; Byte Bites</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-32122</link>
		<dc:creator>Conficker/Downadup worm strikes &#124; Byte Bites</dc:creator>
		<pubDate>Fri, 16 Jan 2009 05:17:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-32122</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Conficker wormÂ (W32/Confick-A, W32/Confick-B, W32/Confick-C, W32/Confick-D), aka Downadup (W32.Downadup, W32.Downadup.B)Â isÂ going around and is capable of spreadingÂ very fast on Windows XP/Vista machines. This worm exploits1 a remote code execution vulnerability in the Server service responsible for file/printer sharing functionalities. The vulnerability is apparently because of a buffer overrun bug in netapi32.dll call NetpwPathCanonicalize. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacker Coder</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-31517</link>
		<dc:creator>Hacker Coder</dc:creator>
		<pubDate>Wed, 17 Dec 2008 14:35:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-31517</guid>
		<description>Is the bug exist in Windows Server 2008?</description>
		<content:encoded><![CDATA[<p>Is the bug exist in Windows Server 2008?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nvedala</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-31381</link>
		<dc:creator>nvedala</dc:creator>
		<pubDate>Wed, 10 Dec 2008 05:00:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-31381</guid>
		<description>Skywing, here is first ever humor book for debugging folks. Available for order on Amazon. I&#039;ve been following your blog for quite long and so in one of the cartoons I&#039;ve included you :) Hope you don&#039;t mind :p

http://www.amazon.com/gp/product/1906717257?ie=UTF8&amp;tag=idebug_in_windbg-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1906717257</description>
		<content:encoded><![CDATA[<p>Skywing, here is first ever humor book for debugging folks. Available for order on Amazon. I&#8217;ve been following your blog for quite long and so in one of the cartoons I&#8217;ve included you :) Hope you don&#8217;t mind :p</p>
<p><a href="http://www.amazon.com/gp/product/1906717257?ie=UTF8&amp;tag=idebug_in_windbg-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1906717257" rel="nofollow">http://www.amazon.com/gp/product/1906717257?ie=UTF8&amp;tag=idebug_in_windbg-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1906717257</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Baumgartner</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-31198</link>
		<dc:creator>Kurt Baumgartner</dc:creator>
		<pubDate>Wed, 03 Dec 2008 01:37:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-31198</guid>
		<description>Awesome post. No need to push off BinDiff because of price...

&quot;For all you hardcore hax0rs, Skywing has put together a detailed post on using the AT service and hiew to to inject the updated code into svchost.exe and manually hot patch the running vulnerable service, avoiding a reboot. Fun reading, but not recommended.
In it he claims that he wasn&#039;t able to use BinDiff to identify the patched code, but for those RE&#039;s with a lack of funding, there is a limited trial version of v2.0 that worked great on netapi32 and helped id this problem as a stack overflow within a couple minutes of Microsoft&#039;s patch release. You can see for yourself what a great tool Bindiff really is -- google is your friend.&quot;

http://blog.threatfire.com/2008/10/microsoft-is-releasing-out-of-cycle.html</description>
		<content:encoded><![CDATA[<p>Awesome post. No need to push off BinDiff because of price&#8230;</p>
<p>&#8220;For all you hardcore hax0rs, Skywing has put together a detailed post on using the AT service and hiew to to inject the updated code into svchost.exe and manually hot patch the running vulnerable service, avoiding a reboot. Fun reading, but not recommended.<br />
In it he claims that he wasn&#8217;t able to use BinDiff to identify the patched code, but for those RE&#8217;s with a lack of funding, there is a limited trial version of v2.0 that worked great on netapi32 and helped id this problem as a stack overflow within a couple minutes of Microsoft&#8217;s patch release. You can see for yourself what a great tool Bindiff really is &#8212; google is your friend.&#8221;</p>
<p><a href="http://blog.threatfire.com/2008/10/microsoft-is-releasing-out-of-cycle.html" rel="nofollow">http://blog.threatfire.com/2008/10/microsoft-is-releasing-out-of-cycle.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil Fultz</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-30481</link>
		<dc:creator>Phil Fultz</dc:creator>
		<pubDate>Wed, 05 Nov 2008 04:53:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-30481</guid>
		<description>You mentioned blocking inbound SMB on both TCP ports 139 and 445 &quot;thus cutting off remote access to the srvsvc pipe, a prerequisite for exploiting the vulnerability&quot;.

While your proposed remedy accomplishes the goal, I think it worthwhile to point out that the srvsvc pipe is not necessarily required to access the vulnerable function.  Because of what appear to be well-known characteristics of Microsoft&#039;s RPC implementation, srvsvc functionality is available over other RPC endpoints registered in-process.  This is noteworthy because one endpoint is the BROWSER named pipe, which has a more permissive DACL than than the SRVSVC named pipe.  As an example of the practical application of this, see the public Metasploit module that exploits this vulnerability.</description>
		<content:encoded><![CDATA[<p>You mentioned blocking inbound SMB on both TCP ports 139 and 445 &#8220;thus cutting off remote access to the srvsvc pipe, a prerequisite for exploiting the vulnerability&#8221;.</p>
<p>While your proposed remedy accomplishes the goal, I think it worthwhile to point out that the srvsvc pipe is not necessarily required to access the vulnerable function.  Because of what appear to be well-known characteristics of Microsoft&#8217;s RPC implementation, srvsvc functionality is available over other RPC endpoints registered in-process.  This is noteworthy because one endpoint is the BROWSER named pipe, which has a more permissive DACL than than the SRVSVC named pipe.  As an example of the practical application of this, see the public Metasploit module that exploits this vulnerability.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Mission Control Supreme Commander Blog - Eintrag-Details: Unfassbar...</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-30429</link>
		<dc:creator>The Mission Control Supreme Commander Blog - Eintrag-Details: Unfassbar...</dc:creator>
		<pubDate>Wed, 29 Oct 2008 11:49:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-30429</guid>
		<description>[...] Unfassbar... [...]</description>
		<content:encoded><![CDATA[<p>[...] Unfassbar&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nksingh</title>
		<link>http://www.nynaeve.net/?p=226&#038;cpage=1#comment-30372</link>
		<dc:creator>nksingh</dc:creator>
		<pubDate>Sun, 26 Oct 2008 09:35:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.nynaeve.net/?p=226#comment-30372</guid>
		<description>I&#039;m not sure why this one was not delivered as a hotpatch.  AMD64 actually requires all functions to be hotpatchable.  They must begin with an opcode bigger than two bytes (so sometimes you get a redundant REX prefix on pushreg instructions at the beginning of a function).  Perhaps it takes too long to generate the hotpatch and test it properly relative to how quickly this bug was turned around from discovery to patch.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure why this one was not delivered as a hotpatch.  AMD64 actually requires all functions to be hotpatchable.  They must begin with an opcode bigger than two bytes (so sometimes you get a redundant REX prefix on pushreg instructions at the beginning of a function).  Perhaps it takes too long to generate the hotpatch and test it properly relative to how quickly this bug was turned around from discovery to patch.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.399 seconds -->
