This forum is in archive mode. You will not be able to post new content.

Author Topic: TTF Vuln - Discuss  (Read 1135 times)

0 Members and 1 Guest are viewing this topic.

Offline imation

  • Peasant
  • *
  • Posts: 141
  • Cookies: 2
    • View Profile
TTF Vuln - Discuss
« on: November 07, 2011, 03:06:37 PM »
Quote
Microsoft has revealed in the advisory that the problem is with the Windows’ TrueType font parsing engine. An attacker who exploits this vulnerability can run their own code in kernel mode and then proceed, unhindered to  install programs; modify data; or create new accounts.

So im doing a bit of research on this vuln that has been pushed and publicisied recently with the duqu virus...
 
does anybody have any info how the true type font can be fettled?
 
Tar
 
iMation


Offline imation

  • Peasant
  • *
  • Posts: 141
  • Cookies: 2
    • View Profile
Re: TTF Vuln - Discuss
« Reply #2 on: November 07, 2011, 04:21:16 PM »
What is T2embed.dll?

T2embed.dll file is a library that renders TrueType fonts on your computer.

How can a font be a source of infection?

Fonts are loaded into memory. For the font renderer to work it clearly has to read input (i.e. the text/font), so the only thing you have to do is craft some text/font/bytestream that leads to some buffer/heap overflow or whatever in the renderer, which then allows you to execute arbitrary code. There is apparently a security hole in the font rendering library that allows things it loads into memory to execute code.


Offline FuyuKitsune

  • Knight
  • **
  • Posts: 292
  • Cookies: 21
    • View Profile
Re: TTF Vuln - Discuss
« Reply #3 on: November 07, 2011, 04:23:48 PM »
I don't think anybody will have information on it unless somebody else finds it independently. Nobody has samples of Duqu (except antivirus companies) because it only infected a few specific computers around the world, so nobody has a chance to see how the exploit works.
Microsoft realized that only a few people are at risk of infection so they aren't patching immediately. If the exploit gets released to the public there will be a patch almost immediately.

Offline imation

  • Peasant
  • *
  • Posts: 141
  • Cookies: 2
    • View Profile
Re: TTF Vuln - Discuss
« Reply #4 on: November 08, 2011, 11:02:14 AM »
After Speaking to a few specialist on Malware i have a little more info. as for the inner working, the symantec pdf is the best read.


 



Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.