Author Topic: Directly running a .zip, kinda  (Read 23929 times)

0 Members and 4 Guests are viewing this topic.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Directly running a .zip, kinda
« on: November 16, 2005, 03:25:38 pm »
This is a tricky way to hide an executable file:

Quote
Was doing some testing [xfocus-AD-051115]

Ie Multiple antivirus failed to scan
malicous filename bypass vulnerability

The system is windows 2000 sp4 srp5 with
all other patches upto date.

At the command prompt cmd.exe execute
the following with the results.

I copy and paste from cmd.exe
-------------------------------------------------------------------

E:\TEMP>cd test

E:\TEMP\test>copy %windir%\system32\calc.exe
        1 file(s) copied.

E:\TEMP\test>ren calc.exe calc.exe.zip

E:\TEMP\test>dir /b
calc.exe.zip

E:\TEMP\test>calc.exe.zip

E:\TEMP\test>
-------------------------------------------------------------------
This bring up the calc.exe on the screen.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


It actually doesn't matter what the extension is.  .exe.txt.zip.exe.pdf will still run.

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: Directly running a .zip, kinda
« Reply #1 on: January 03, 2006, 10:51:25 pm »
Isn't this kind of like the "exploit" we found on Apache with it parsing stuff.php.rar as a PHP file?

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: Directly running a .zip, kinda
« Reply #2 on: January 03, 2006, 10:54:16 pm »
Yes, in the thread on full-disclosure this issue was referenced. :)

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: Directly running a .zip, kinda
« Reply #3 on: January 03, 2006, 11:03:38 pm »
Yes, in the thread on full-disclosure this issue was referenced. :)

Hehe. :)

Offline ink

  • Newbie
  • *
  • Posts: 74
    • View Profile
Re: Directly running a .zip, kinda
« Reply #4 on: February 14, 2006, 02:59:22 pm »
Isn't that somewhat of a non-issue if you have settings set to show file extensions?

Another neat thing is using SFX scripting in winrar to make self-extracting archieves

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: Directly running a .zip, kinda
« Reply #5 on: February 20, 2006, 05:58:25 pm »
Isn't that somewhat of a non-issue if you have settings set to show file extensions?

Another neat thing is using SFX scripting in winrar to make self-extracting archieves

You're good at digging up old topics! ;D

Haha, yeah.  This doesn't really matter as you're pretty much telling Windows to execute it as an application when you type a filename in a command prompt.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: Directly running a .zip, kinda
« Reply #6 on: February 20, 2006, 07:24:38 pm »
Isn't that somewhat of a non-issue if you have settings set to show file extensions?

Yes, but Windows' traditional "beauty before safety/functionality" view ensured that that's off by default.  Big mistake, in my opinion. 

Offline ink

  • Newbie
  • *
  • Posts: 74
    • View Profile
Re: Directly running a .zip, kinda
« Reply #7 on: February 20, 2006, 07:47:47 pm »
Don't worry, the Windows Vista 'revolution' will fix all that! Ahha  :D

Another way to trick people is using either Winzip or Winrar, you can rename a file to something like:
"MaliciousFile.doc                                                             .exe"

That way when you add it to the archieve it looks like:

MaliciousFile.doc                           ..
and using Reshack you can easily change the .exe icon to a .doc icon
« Last Edit: February 20, 2006, 07:49:48 pm by ink »

Offline Sidoh

  • x86
  • Hero Member
  • *****
  • Posts: 17634
  • MHNATY ~~~~~
    • View Profile
    • sidoh
Re: Directly running a .zip, kinda
« Reply #8 on: February 20, 2006, 07:49:22 pm »
Don't worry, the Windows Vista 'revolution' will fix all that! Ahha  :D

ROFL.

Offline Warrior

  • supreme mac daddy of trolls
  • Hero Member
  • *****
  • Posts: 7503
  • One for a Dime two for a Quarter!
    • View Profile
Re: Directly running a .zip, kinda
« Reply #9 on: February 20, 2006, 07:54:05 pm »
Don't worry, the Windows Vista 'revolution' will fix all that! Ahha  :D

You're damn right, but you'd be too busy misinterpreting text to figure out how to install it
at the least.
One must ask oneself: "do I will trolling to become a universal law?" And then when one realizes "yes, I do will it to be such," one feels completely justified.
-- from Groundwork for the Metaphysics of Trolling

Offline ink

  • Newbie
  • *
  • Posts: 74
    • View Profile
Re: Directly running a .zip, kinda
« Reply #10 on: February 20, 2006, 08:01:37 pm »
lol yes I'm sure installing a Windows product will be very difficult, I'm not sure if I can handle a revolutionary install wizard!

Offline Warrior

  • supreme mac daddy of trolls
  • Hero Member
  • *****
  • Posts: 7503
  • One for a Dime two for a Quarter!
    • View Profile
Re: Directly running a .zip, kinda
« Reply #11 on: February 20, 2006, 08:04:16 pm »
You might think it's disabled by default.
One must ask oneself: "do I will trolling to become a universal law?" And then when one realizes "yes, I do will it to be such," one feels completely justified.
-- from Groundwork for the Metaphysics of Trolling

Offline ink

  • Newbie
  • *
  • Posts: 74
    • View Profile
Re: Directly running a .zip, kinda
« Reply #12 on: February 20, 2006, 08:05:49 pm »
Hawhaw! If I were to base my judgement off previous Microsoft products, I'd say yes, file extentions will be disabled by default.

Offline Warrior

  • supreme mac daddy of trolls
  • Hero Member
  • *****
  • Posts: 7503
  • One for a Dime two for a Quarter!
    • View Profile
Re: Directly running a .zip, kinda
« Reply #13 on: February 20, 2006, 08:07:32 pm »
Most likely, I turn them on personally. Mostly because to make "PHP" files I make textfiles then rename the extension. Otherwise I'd leave them off.
One must ask oneself: "do I will trolling to become a universal law?" And then when one realizes "yes, I do will it to be such," one feels completely justified.
-- from Groundwork for the Metaphysics of Trolling

Offline ink

  • Newbie
  • *
  • Posts: 74
    • View Profile
Re: Directly running a .zip, kinda
« Reply #14 on: February 20, 2006, 08:09:51 pm »
I turn them on because looks can be decieving.