<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More Details on &quot;Operation Aurora&quot;</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2010/01/14/more-details-on-operation-aurora/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: G.E. Pelletier</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26143</link>
		<dc:creator>G.E. Pelletier</dc:creator>
		<pubDate>Wed, 20 Jan 2010 13:41:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26143</guid>
		<description>Hi Rahul,

Yesterday&#039;s tests on UDS Version III were sucessful. The false positive rate is very low. Only two were detected out of about 50 million requests to about 140,000 unique domain names on the Internet. These appear to be caused by the same script, with slight customisations for each site:

http://ce2.gcion.net/scripts/GDSRScripts.js

The VirusTotal analysis of the file:
http://www.virustotal.com/analisis/fb876196bf52422ca21091610e3a1d396cadf2156f4f378ce34e896150236696-1263990391


http://www.rgj.com/scripts/GDSRScripts.js

VirusTotal Report:
http://www.virustotal.com/analisis/d34174e1bb395530e9fd2de036bb48a4580250942acb310eaccc65a039758353-1263991051

These have been updated in our IntruShield SR.

Sincerely,

G.E. Pelletier</description>
		<content:encoded><![CDATA[<p>Hi Rahul,</p>
<p>Yesterday&#8217;s tests on UDS Version III were sucessful. The false positive rate is very low. Only two were detected out of about 50 million requests to about 140,000 unique domain names on the Internet. These appear to be caused by the same script, with slight customisations for each site:</p>
<p>http://ce2.gcion.net/scripts/GDSRScripts.js</p>
<p>The VirusTotal analysis of the file:<br />
http://www.virustotal.com/analisis/fb876196bf52422ca21091610e3a1d396cadf2156f4f378ce34e896150236696-1263990391</p>
<p>http://www.rgj.com/scripts/GDSRScripts.js</p>
<p>VirusTotal Report:<br />
http://www.virustotal.com/analisis/d34174e1bb395530e9fd2de036bb48a4580250942acb310eaccc65a039758353-1263991051</p>
<p>These have been updated in our IntruShield SR.</p>
<p>Sincerely,</p>
<p>G.E. Pelletier</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G.E. Pelletier</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26142</link>
		<dc:creator>G.E. Pelletier</dc:creator>
		<pubDate>Tue, 19 Jan 2010 12:27:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26142</guid>
		<description>Hi Rahul,

Thank you for the information about signature 0Ã—4022f900. This will help us.

The exploit was fully tested on three systems with HIPs installed. It was effective on all three (IE 6 disappeared and the calculator popped up). Paradoxically, the HIPs logs also show the attack as being prevented. We will follow up with McAfee.

An SR was opened with McAfee with respect to the IntruShield false positives on the UDS Version II. I have advised the technician that the signature was updated to correct the false positives.

I will be testing the UDS Version III update this morning.

Again, your help is greatly appreciated.

Sincerely,

G.E. Pelletier</description>
		<content:encoded><![CDATA[<p>Hi Rahul,</p>
<p>Thank you for the information about signature 0Ã—4022f900. This will help us.</p>
<p>The exploit was fully tested on three systems with HIPs installed. It was effective on all three (IE 6 disappeared and the calculator popped up). Paradoxically, the HIPs logs also show the attack as being prevented. We will follow up with McAfee.</p>
<p>An SR was opened with McAfee with respect to the IntruShield false positives on the UDS Version II. I have advised the technician that the signature was updated to correct the false positives.</p>
<p>I will be testing the UDS Version III update this morning.</p>
<p>Again, your help is greatly appreciated.</p>
<p>Sincerely,</p>
<p>G.E. Pelletier</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rahul Kashyap</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26141</link>
		<dc:creator>Rahul Kashyap</dc:creator>
		<pubDate>Tue, 19 Jan 2010 01:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26141</guid>
		<description>Hello Pelletier,
Regarding the HIPS protection, we&#039;ve successfully verified that HIPS blocks the exploit out of the box. While verifying such exploits you&#039;ll need to ensure that the exploit is successful on the victim machine. If you have further questions on this, please contact your SE/McAfee representative so that we can resolve the issues you&#039;re encountering.

Regards</description>
		<content:encoded><![CDATA[<p>Hello Pelletier,<br />
Regarding the HIPS protection, we&#8217;ve successfully verified that HIPS blocks the exploit out of the box. While verifying such exploits you&#8217;ll need to ensure that the exploit is successful on the victim machine. If you have further questions on this, please contact your SE/McAfee representative so that we can resolve the issues you&#8217;re encountering.</p>
<p>Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rahul Kashyap</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26140</link>
		<dc:creator>Rahul Kashyap</dc:creator>
		<pubDate>Tue, 19 Jan 2010 01:24:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26140</guid>
		<description>Hello Pelletier,

This exploit is detect by IntruShield out of the box with generic JavaScript Shellcode signatures (no need to update to block this exploit)
&#039;HTTP: Possible attempt to create javascript shellcode:1&#039; :0x4022f900

Regarding the False Positives, we&#039;ve isolated the issue and updated the UDS and it&#039;ll be out today.</description>
		<content:encoded><![CDATA[<p>Hello Pelletier,</p>
<p>This exploit is detect by IntruShield out of the box with generic JavaScript Shellcode signatures (no need to update to block this exploit)<br />
&#8216;HTTP: Possible attempt to create javascript shellcode:1&#8242; :0x4022f900</p>
<p>Regarding the False Positives, we&#8217;ve isolated the issue and updated the UDS and it&#8217;ll be out today.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G.E. Pelletier</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26139</link>
		<dc:creator>G.E. Pelletier</dc:creator>
		<pubDate>Mon, 18 Jan 2010 18:58:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26139</guid>
		<description>VSE, BOP, IntruShield UDS, and HIPS do not protect against the following exploit code:

http://ahmed.obied.net/software/code/exploits/ie_aurora.py

The above exploit code is very effective with IE 6.

The IntruShield UDS-HTTP: Microsoft Internet Explorer HTML DOM Memory Corruption dated 14 Jan 2010 fails to detect this.

The updated (version II) IntruShield UDS-HTTP: Microsoft Internet Explorer HTML DOM Memory Corruption II dated 16 Jan 2010. Generates massive numbers of false postives (over 100 in 20 minutes).

The exploit code was originally found in the comments of the ISC SANS story:
http://isc.sans.org/diary.html?storyid=8002</description>
		<content:encoded><![CDATA[<p>VSE, BOP, IntruShield UDS, and HIPS do not protect against the following exploit code:</p>
<p>http://ahmed.obied.net/software/code/exploits/ie_aurora.py</p>
<p>The above exploit code is very effective with IE 6.</p>
<p>The IntruShield UDS-HTTP: Microsoft Internet Explorer HTML DOM Memory Corruption dated 14 Jan 2010 fails to detect this.</p>
<p>The updated (version II) IntruShield UDS-HTTP: Microsoft Internet Explorer HTML DOM Memory Corruption II dated 16 Jan 2010. Generates massive numbers of false postives (over 100 in 20 minutes).</p>
<p>The exploit code was originally found in the comments of the ISC SANS story:<br />
http://isc.sans.org/diary.html?storyid=8002</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26135</link>
		<dc:creator>John</dc:creator>
		<pubDate>Fri, 15 Jan 2010 23:49:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26135</guid>
		<description>Craig, great to hear that.  Truly a great product that we hope to see and hear more about in the future.  Thanks for setting me straight.</description>
		<content:encoded><![CDATA[<p>Craig, great to hear that.  Truly a great product that we hope to see and hear more about in the future.  Thanks for setting me straight.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Schmugar</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26133</link>
		<dc:creator>Craig Schmugar</dc:creator>
		<pubDate>Fri, 15 Jan 2010 19:21:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26133</guid>
		<description>John, no languishing going on here, I updated the blog to note the McAfee Web Gateway (formerly Webwasher) and TrustedSource coverage information.</description>
		<content:encoded><![CDATA[<p>John, no languishing going on here, I updated the blog to note the McAfee Web Gateway (formerly Webwasher) and TrustedSource coverage information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://blogs.mcafee.com/mcafee-labs/more-details-on-operation-aurora/comment-page-1#comment-26132</link>
		<dc:creator>John</dc:creator>
		<pubDate>Fri, 15 Jan 2010 01:15:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=3622#comment-26132</guid>
		<description>Why wouldn&#039;t McAfee release some type of protection for the recently acquired Secure Computing Web Gateway (Webwasher) or Firewall (Sidewinder)?  It&#039;s sad when companies acquire smaller better companies and then let the products languish for various reasons.</description>
		<content:encoded><![CDATA[<p>Why wouldn&#8217;t McAfee release some type of protection for the recently acquired Secure Computing Web Gateway (Webwasher) or Firewall (Sidewinder)?  It&#8217;s sad when companies acquire smaller better companies and then let the products languish for various reasons.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

