12 ms·
Windows 7 Update appears to be compromised?
- gizmodo59 11y agoCan anyone shed some light on this?
- imperialdrive 11y agoI've been deploying Microsoft based computer networks for 18 years... this would nearly top my nightmare list! I can't imagine what the alert level is at MS offices right now, but I bet they are expending every effort to get to the bottom of this ASAP :/
- astrodust 11y agoIs this a "lock the doors, man the battle stations" kind of problem? It seems super, super bad.
- dpark 11y agoI doubt it. It looks to me a lot more like a test update that was pushed to production unintentionally rather than malware. A server compromise pushing malware as an update would presumably try to make the update look legitimate in order to maximize how long it went undetected. Disclosure: MSFT employee, no knowledge of this beyond what I've read in this thread, though.
- richmarr 11y ago> a test update that was pushed to production unintentionally rather than malware This position seems to be based on the assumption that malware is less likely to be subject to mistakes than MSFT. Want to check with the PR dept? ;)
- pyre 11y agoYou could rephrase that as: > A test update getting accidentally pushed out is more likely than a compromise of the Windows Update system.
- dpark 11y agoIt's based on the assumption that it's more likely that someone made a harmless but embarrassing mistake than that someone shipped a major security bug in a critical system, which was then exploited by someone simultaneously skilled enough to hijack the Windows Update servers to deliver malware and incompetent enough to completely screw it up. Random text but real TLDs also just smells like test data to me. Someone smarter than me could probably do the statistical analysis to determine if this is actually random or pseudo-random garbage typed by a person. Given the fairly long runs of all-caps and all-lowercase in the description, I'd guess a person typed this out (presumably as part of creating a test or test suite).
- astrodust 11y agoExactly as predicted: http://arstechnica.com/security/2015/09/nerves-rattled-by-highly-suspicious-windows-update-delivered-worldwide/ http://arstechnica.com/security/2015/09/nerves-rattled-by-hi... Also, big whoops.
- A010 11y agoThey've gone through the process to put the "test" update to production servers, so I'm pretty sure this is intentioned. Though they might thought this is ok wo/ harms.
- buffoon 11y agoAppeared on WSUS as well... NEVER turn on auto updates on windows. Read all the KBs, then choose to install, ALWAYS. If you have a corp network, use WSUS and stop all updates and check them. If the KB is content-free like the new ones, no install. I avoided the whole CEIP bag of shit and Windows 10 upgrade notification hell thanks to that.
- imperialdrive 11y agoVery good advice... I agree. Took me a long time to figure that system out, but it sure works well!
- moron4hire 11y agoAlways turn on auto-updates. The likelihood of you missing or delaying an update and getting hit by an a known exploit is a lot more likely than an exploit getting through the update system or enabling a new exploit.
- buffoon 11y agoNo no no no no. I've watched entire networks of machines downed with auto-updates. Always read, always test.
- moron4hire 11y agoIt might make sense to pay a guy to make this his job for hundreds of computers on a corporate network, but there is no way in hell I'm keeping that close of track of updates on my home computer. And when was this, over a decade ago? Also, what evidence did you have it was the auto-update system that caused the outage? Past performance is not a predictor of future performance. Seriously folks, turn on auto-updates.
- buffoon 11y agoThis was Oct 2014. KB2949927.
- mjevans 11y agoI'm worried about friends, family, and small businesses that run Windows with install updates set to automated mode... Shouldn't Microsoft be signing updates so that redirection attacks don't work? Edit: Elaborating on my question; I mean much more like Linux distributions which sign both packages (updates) and the index of those files. Some distributions use multiple hashs/digests to make collision attacks far less likely to succeed. Such an attack could be either the traffic at layer 3 redirected via router compromise, via some name resolution weakness (possibly even to localhost as a way of malware upgrading from being able to edit the hosts file to having system level services). The signing of both the update files and the list of updates could offer protection from an attack that would thus need to be valid for all of the signature checks, not just a single check.
- steven777400 11y agoI'm pretty sure Microsoft does sign updates. Which means either this is a glitch of some kind, or is being refused/failing installation because it's not signed ... Or, worse case, it means the update signing key has been compromised.
- zappo2938 11y agoWhat does 'sign' mean in this context? I hear it a lot and don't understand the mechanism.
- vutekst 11y agohttps://en.wikipedia.org/wiki/Digital_signature https://en.wikipedia.org/wiki/Digital_signature
- SeldomSoup 11y agoIt's a cryptographic mechanism. MS has a private key they apply to each Windows update to mathematically prove A) they're the ones who issued it and B) the content was not modified in transit. (I am not experienced in cryptography. This explanation might be a little simplistic.)
- 11y ago
- LinuxBender 11y agoCould it be that older versions of windows (2k3 for example) might allow this update to be installed? Has anyone tested this in a sandbox?
- MichaelGG 11y agoI'd be surprised if an attacker would waste a compromise with something obvious. Perhaps it's some testing thing that wasn't supposed to go out.
- poizan42 11y agoOr maybe it has been exploited for a long time without anyone noticing it, and now the attackers screwed up?
- politician 11y agoOr a recent update to the infrastructure introduced a breaking change in a previously working malware package.
- blinkingled 11y agoNot seeing anything on my Win7Pro SP1 VM - last update was 4.3MB VC++ 2008 Security fix - MFC applications being vulnerable to DLL planting due to MFC not specifying the full path to system/localization DLLs.
- pyre 11y ago> 4.3MB Interesting that the update in question is also 4.3MB?
- blinkingled 11y agoRight, that's why I brought it up - it also relates to localization which may or may not be related. But interesting none the less.
- cwyers 11y agoIf someone has managed to compromise Windows Update (which I doubt seriously based on what's presented here), why on Earth would they not bother to come up with text more convincing than the garbage on display here?
- markbnj 11y agoYeah I'd say it's more likely someone or something in the update toolchain screwed up.
- chengiz 11y agoThe other option is a deliberate "ethical" hack.
- cwyers 11y agoWouldn't that also call for putting in text that at least makes it clear it's an ethical hack? The only explanation for that garbage is either lorem ipsit filler text (something never meant to get out) or the theory buffoon had about it being a hash collision.
- buffoon 11y agoThat might have been the only text that allowed the updated to be signed.
- dpark 11y agoThat's an interesting theory, but seems unlikely given that the TLDs are all real. Also that would imply a successful hash collision attack which seems exceedingly unlikely. And if true, why not mutate some random bytes in the payload to get the collision rather than the update text (which also may not actually even be stored as part of the signed update).
- anonymfus 11y agoMay be their attack is so specific that they could only use Microsoft signed files in update payload, so they send old vulnerable versions.
- jimrandomh 11y agoThis links to a Microsoft support thread in which several users are reporting a suspicious update distributed through Windows Update. In lieu of a title and description, the update has 108-character and 24-character base52-encoded random numbers. In lieu of "more information" and "help and support" links, it has similarly random base52-encoded domains, which currently do not resolve, in .gov, .edu and .mil. Searching for the patch title turns up a bunch of people asking about the same suspicious patch on other sites, all within the past day. The update is attracting attention because it fails to install. http://security.stackexchange.com/questions/101520/weird-windows-update http://security.stackexchange.com/questions/101520/weird-win... https://www.reddit.com/r/techsupport/comments/3mykv1/weird_windows_update/ https://www.reddit.com/r/techsupport/comments/3mykv1/weird_w... This does strongly suggest a compromise of the Windows Update servers or of some bit of infrastructure that connects people to them, but also suggests that whoever the attackers are, they made a mistake - a successful compromise executed correctly would not leave so much evidence around. It's quite possible that they've been compromised for awhile, and this is a buggy update to the existing malware.
- dpark 11y ago"Base52-encoded random numbers" is a rather obtuse way to describe random letters.
- dragontamer 11y agoBase52 means capital letters and lower case letters. Base62 includes numbers (0 through 9). We programmers like being specific. Sometimes these sorts of details matter.
- dpark 11y agoThis detail doesn't matter and is needlessly confusing. "Random upper and lowercase letters" is exactly as specific and accurate as "base52-encoded random numbers", but the former is more understandable while the latter is trying way too hard to sound smart.
- JohnTHaller 11y agoThere is a chance that the machines affected were already compromised by malware which altered the way Windows Update was working.
- RIMR 11y agoWouldn't that malware just download and install payloads itself rather than piggybacking off of Windows update? It would need root access to manipulate Windows Update in this way, but with root access it wouldn't need Windows Update to install packages.
- JohnTHaller 11y agoIt would allow the malware to get around any software firewalls.
- RIMR 11y agoWhich it would already have control of with root access.
- JohnTHaller 11y agoIt would, but it would need to deal with the whole plethora of software firewall to ensure it doesn't trip them but doesn't break them in a way noticeable by the user. Piggybacking on Windows Update accomplishes both because every software firewall has Windows Update whitelisted out of the box.
- angelbob 11y agoSeveral of the forum comments mention fresh installs. So possible, but fairly unlikely.
- JohnTHaller 11y agoFresh installs from what media though? "Pre-activated" Windows ISOs are freely available on any torrent search site with who-knows-what added.
- jimrandomh 11y agoDoes anyone have a copy of the 4.3MB file that this refers to? If so, please: (1) submit it to VirusTotal, and (2) post it here.
- hodwik 11y agoThis is probably just a test update that went out by mistake. If MSFT is anything like where I work, that "payload" is a picture of a cat.
- Zirro 11y agoMicrosoft _should_ not be anything like where you work. I'm not a Windows-user, but if I were I would hope and expect that the update mechanism for one of the worlds most used pieces of software was closely guarded by several layers of computer-based signing and human approval.
- odonnellryan 11y agoThere are certainly test environments that these updates are pushed to much more freely than the production environment. Mistakes happen.
- Zirro 11y agoI certainly understand what you are saying, but I must repeat the essence of my previous post. For something so critical, there should simply be too many safeguards for any test to make it through all the way to end users. If a test update really did make it through, it would warrant significant questioning of the procedures at Microsoft. If a test could get through without being discovered, then so might malicious code.
- jdmichal 11y ago> For something so critical, there should simply be too many safeguards for any test to make it through all the way to end users. The only way to guarantee that is to not allow updates to be published at all. > If a test could get through without being discovered, then so might malicious code. You are conflating very different things. MSFT being able to publish updates is normal and does not require a security breach, even if one particular update shouldn't have been published. An external entity being able to publish an update containing malicious code would be a huge security breach, requiring both the ability to sign the update and to publish it.
- mtgx 11y agoMicrosoft sending spyware again?
- solidangle 11y agoCould it be a man in the middle that tries to install updates that aren't signed by Microsoft? It reminds me of this: http://www.leviathansecurity.com/blog/the-case-of-the-modified-binaries/ http://www.leviathansecurity.com/blog/the-case-of-the-modifi... .
- arca_vorago 11y agoLooks more like an internal flub: "//rr1winwusfs04/c/msdownload/update/software/defu/2015/09/testexe_896e3a62-8954-447b-5a562bd65cc6_d5e430cb05ee8a627ee6d811da8d7c4ccea57f4b.exe" That being said, that something like this could happen should raise lots of questions about the amount of oversight on updates hitting windows, and the general security of such systems. I'll wait for an official response or a reverse engineer before I decide what's going on here.
- flyinghamster 11y agoI haven't seen any randomly-named updates on my system - but I had earlier ripped out all the telemetry and Windows 10-related crap (KB2952664, KB3021917, KB3035583, KB3068708, KB3075249, and KB3080149) and marked them hidden. I've also set my update policy to notify-only. Now the spy updates are not hidden, and marked as "Important." They're bound and determined to force this crap down our throats. Bastards. "Because f*ck you, that's why." The rallying cry of the corporate world.
- listic 11y agoCould you please elaborate on how you did that?
- flyinghamster 11y agoNote this is Windows 7. I uninstalled each of those KBs manually from the "Installed Updates" screen, then changed the update policy. I used to use "download and install manually" but now I'd prefer only being notified, and THEN deciding whether or not I want to download whatever is offered. I then re-ran the check for updates, and hid the offending KBs. That was earlier this month. After reading this article, I decided to have a look and see if there was anything fishy in my update history (beyond the listed KBs that I don't want). Nothing there, at least, but my hidden updates were un-hidden (along with Silverlight and Skype, two more "do not want" things that I always hide).
- orthecreedence 11y agoNote you can remove updates from Control Panel -> Programs and Features -> View Installed Updates (link on the left sidebar).
- Animats 11y agoWhere's Microsoft on this? This is on two news outlets as well as HN. Microsoft PR needs to issue a statement in the next hour or two, even one that just says they're investigating the issue, or it will be on the evening TV news.
- rtkwe 11y agohttp://arstechnica.com/security/2015/09/nerves-rattled-by-highly-suspicious-windows-update-delivered-worldwide/ http://arstechnica.com/security/2015/09/nerves-rattled-by-hi... It's already done. About 5 hours after the post was first opened on the forum. There's also an article on ZDNet. http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/ http://www.zdnet.com/article/microsoft-accidentally-issued-a...
- ArtDev 11y agohttp://arstechnica.com/security/2015/09/nerves-rattled-by-highly-suspicious-windows-update-delivered-worldwide/ http://arstechnica.com/security/2015/09/nerves-rattled-by-hi...
- comex 11y agoJust to state the obvious, .gov, .edu, and .mil are all restricted TLDs run by the US. What kind of attacker uses domain names in their attack that they can't register? Unless, of course... But that would be a wee bit obvious.
- xamolxix 11y ago> Unless, of course... Unless the servers are compromised and used as C&C?
- eloy 11y agoConfirmed that it was a test update: http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/ http://www.zdnet.com/article/microsoft-accidentally-issued-a...
- AdmiralAsshat 11y agoConsidering the panic it generated, some sort of official response, apology, etc. would be nice rather than simply giving a terse "We goofed" response to a third party.
- odonnellryan 11y agoThese things take time, at least a few hours, on the corporate level. We've seen responses from MS before about similar issues.
- ChuckMcM 11y agoI saw that, and was wondering about it. Seems like a complete failure of the testing protocol, or a complete exposure of the partnership Microsoft has with someone invested in having something installed on a Windows 7 machine :-). Normally I'm not nearly that tin-hattish but with the disclosures of what people do these days, one wonders ...
- gauravphoenix 11y agoI find it interesting that MS would use following URLs even though it was a test update https://hckSLpGtvi.PguhWDz.fuVOl.gov https://hckSLpGtvi.PguhWDz.fuVOl.gov https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu
- alexforster 11y agoBoth are well-known TLDs that can't be acquired without verification by the US government. Presumably the assumption is that these URLs can be guaranteed to never exist.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- jordigh 11y agoDon't panic, it was just a boo-boo: http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/ http://www.zdnet.com/article/microsoft-accidentally-issued-a...
- ComodoHacker 11y agoToo many "tests" this month, I'd say. Test cert, test update... Let's hope something worse like "test nuclear strike" won't follow.
- acqq 11y agoAnd the same company doesn't allow the users of the Windows 10 Home to review the updates, instead, the Windows 10 Home updates always download and install.