{"id":84323,"date":"2017-05-29T22:19:02","date_gmt":"2017-05-30T02:19:02","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-08-09T14:20:39","modified_gmt":"2021-08-09T18:20:39","slug":"windows-terrible-horrible-no-good-month","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/windows-terrible-horrible-no-good-month\/","title":{"rendered":"Windows Terrible, Horrible, No Good Month"},"content":{"rendered":"<p><a href=\"https:\/\/knowyourmeme.com\/photos\/734424-windows-xp-bliss-wallpaper\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-119324 size-medium\" title=\"Windows Terrible, Horrible, No Good Month\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/WIndow_broke.jpg?resize=150%2C94&#038;ssl=1\" alt=\"Windows Terrible, Horrible, No Good Month\" width=\"150\" height=\"94\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/WIndow_broke.jpg?resize=150%2C94&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/WIndow_broke.jpg?resize=75%2C47&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/WIndow_broke.jpg?w=680&amp;ssl=1 680w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>Redmond&#8217;s <a href=\"https:\/\/www.amazon.com\/Alexander-Terrible-Horrible-Classic-Board\/dp\/1442498161\" target=\"_blank\" rel=\"noopener noreferrer\">Terrible, Horrible, No Good, Very Bad <\/a>month continues. The <a href=\"http:\/\/www.telegraph.co.uk\/technology\/0\/ransomware-does-work\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>WannaCry<\/strong> ransomware<\/a> hit <a href=\"https:\/\/www.theverge.com\/2017\/5\/19\/15665488\/wannacry-windows-7-version-xp-patched-victim-statistics\" target=\"_blank\" rel=\"noopener noreferrer\">mostly Windows 7 machines<\/a>, and now researchers from the Russian information security company Aladdin RD recently discovered a <strong>new bug<\/strong> that will slow down and <strong>crash <a title=\"Microsoft\" href=\"http:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a><\/strong> (<a title=\"NASDAQ | MSFT\" href=\"https:\/\/www.google.com\/finance?cid=358464\" target=\"_blank\" rel=\"noopener noreferrer\">MSFT<\/a>) Windows <strong><a href=\"http:\/\/www.cnbc.com\/2017\/03\/16\/microsoft-killing-windows-vista-heres-what-you-should-do.html\" target=\"_blank\" rel=\"noopener noreferrer\">Vista<\/a><\/strong>, <strong><a href=\"http:\/\/www.pcmag.com\/article2\/0,2817,2475079,00.asp\" target=\"_blank\" rel=\"noopener noreferrer\">Windows 7<\/a>, <\/strong>and <strong><a href=\"https:\/\/techcrunch.com\/2016\/01\/12\/microsoft-today-ends-support-for-windows-8-old-versions-of-internet-explorer\/\" target=\"_blank\" rel=\"noopener noreferrer\">Windows 8<\/a> <\/strong>PCs, but does not seem to impact Windows 10 so far.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"Microsoft logo\" src=\"https:\/\/i0.wp.com\/assets.onestore.ms\/cdnfiles\/external\/uhf\/long\/9a49a7e9d8e881327e81b9eb43dabc01de70a9bb\/images\/microsoft-gray.png?resize=150%2C32&#038;ssl=1\" alt=\"Microsoft logo\" width=\"150\" height=\"32\" \/><\/a>In a <a href=\"http:\/\/www.makeuseof.com\/tag\/3-windows-98-bugs-worth-revisiting\/\" target=\"_blank\" rel=\"noopener noreferrer\">throwback to the Windows 95<\/a> and 98 era, <a href=\"https:\/\/arstechnica.co.uk\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Ars Technica<\/em><\/a> <a href=\"https:\/\/arstechnica.co.uk\/information-technology\/2017\/05\/in-a-throwback-to-the-90s-ntfs-bug-lets-anyone-hang-or-crash-windows-7-8-1\/\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> that certain <strong>specially crafted filenames<\/strong> could make the operating system lock up or occasionally <strong>crash with a <a href=\"https:\/\/www.techopedia.com\/definition\/3323\/blue-screen-of-death-bsod\" target=\"_blank\" rel=\"noopener noreferrer\">blue screen of death<\/a><\/strong>. <em>Ars<\/em> reports that the bug allows a malicious website to try to load an image file with the <strong>\u201c$MFT<\/strong>\u201d name in the directory path. Windows uses \u201c$MFT\u201d for special metadata files that are used by the <a href=\"http:\/\/searchwindowsserver.techtarget.com\/definition\/NTFS\" target=\"_blank\" rel=\"noopener noreferrer\">NTFS file system<\/a>. The effected systems do not handle this directory name correctly.<\/p>\n<p>The file exists in the root directory of each NTFS volume, but the NTFS driver handles it in special ways. <em>Ars<\/em> explains that it&#8217;s hidden from view and inaccessible to most software. Attempts to open the file are normally blocked, but if the filename is used as if it were a <strong>directory name<\/strong>\u2014for example, trying to open the file c:\\$MFT\\123\u2014then the NTFS driver takes out a <strong>lock on the file and never releases it<\/strong>. Every subsequent operation sits around waiting for the lock to be released. <strong>Forever.<\/strong> This blocks all other attempts to get access to the file system, and so every program will start to hang, rendering the machine <strong>unusable until it is rebooted<\/strong>.<\/p>\n<p><em><a href=\"https:\/\/www.computerhope.com\/jargon\/d\/ddos.htm\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"DDoS\" src=\"https:\/\/www.computerhope.com\/jargon\/d\/ddos.htm\" alt=\"DDoS\" width=\"142\" height=\"105\" \/><\/a>Ars<\/em> says that web pages that use the bad filename in an image source will provoke the bug and make the machine stop responding. Depending on what the machine is doing concurrently, it will sometimes blue screen. Either way, you&#8217;re going to need to reboot it to recover. Some browsers will block attempts to access these local resources, but Internet Explorer will try to open the bad file.<\/p>\n<p><em>Ars<\/em> couldn&#8217;t immediately cause the same thing to occur remotely (by sending <a href=\"http:\/\/searchwindowsserver.techtarget.com\/definition\/IIS\" target=\"_blank\" rel=\"noopener noreferrer\">IIS<\/a> a request for a bad filename), but it wouldn&#8217;t immediately surprise us if certain configurations or trickery were enough to cause the same problem.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20170829163942\/http:\/\/gizmodo.com:80\/5129919\/what-a-windows-7-bsod-looks-like\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"Windows Blue Screen of Death\" src=\"https:\/\/i0.wp.com\/i.kinja-img.com\/gawker-media\/image\/upload\/s--ZS-yaEHt--\/c_scale%2Cfl_progressive%2Cq_80%2Cw_800\/18mkh1rs9eua3jpg.jpg?resize=165%2C118&#038;ssl=1\" alt=\"Windows Blue Screen of Death\" width=\"165\" height=\"118\" \/><\/a><a href=\"https:\/\/www.theverge.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>The Verge<\/em><\/a> has <a href=\"https:\/\/www.theverge.com\/2017\/5\/26\/15696704\/microsoft-windows-7-windows-8-pc-crash-bug-ntfs\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>successfully tested<\/strong> the bug<\/a> on a Windows 7 PC with the default <strong>Internet Explore<\/strong>r browser. Using a filename with \u201cc:\\$MFT\\123\u201d in a <strong>website image<\/strong>, their test caused a machine to slow down to the point they had to reboot to get the PC working again.<\/p>\n<p>A Microsoft spokesperson <a href=\"https:\/\/www.engadget.com\/2017\/05\/26\/windows-7-vista-8-vulnerability\/\" target=\"_blank\" rel=\"noopener noreferrer\">told<\/a> <em><a href=\"https:\/\/www.engadget.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Engadget<\/a><\/em> that the company is looking into the matter and will give an update as soon as it can.<br \/>\n<em>&#8220;Our engineers are currently reviewing the information. Microsoft has a customer commitment to investigate reported security issues and provide updates as soon as possible.&#8221;<\/em><\/p>\n<p>The Redmond boys also had to release an emergency <a href=\"http:\/\/whatis.techtarget.com\/definition\/out-of-band-patch\" target=\"_blank\" rel=\"noopener noreferrer\">out-of-band<\/a> update for the Malware Protection Engine aka <a href=\"https:\/\/www.microsoft.com\/en-us\/safety\/pc-security\/windows-defender.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Defender<\/a>. Two Google security researchers discovered the &#8220;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-researchers-find-wormable-crazy-bad-windows-exploit\/\" target=\"_blank\" rel=\"noopener noreferrer\">crazy bad<\/a>&#8221; flaw. They claimed it was &#8220;the worst Windows remote code exec in recent memory.&#8221; The <a href=\"https:\/\/technet.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">TechNet<\/a> <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/4022344.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">article <\/a>says the vulnerability they patched would allow remote code execution if the Microsoft Malware Protection Engine scans a specially crafted file (<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-0290\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2017-0290<\/a>). To MSFT&#8217;s credit, they did fix the bug and release the patch with a week of being notified.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em>Early reports are that this bug is an attack vector. However, this is a <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/denial-of-service\" target=\"_blank\" rel=\"noopener noreferrer\">denial of service attack<\/a> that will need a reboot. This new flaw could be bundled with other more dangerous malware to force the user to reboot allowing the attacking malware to get loaded.<\/em><\/p>\n<p><strong>Related articles<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/www.theregister.co.uk\/2017\/05\/29\/microsoft_out_of_band_patches\/\" target=\"_blank\" rel=\"noopener noreferrer\"> Microsoft patched more Malware Protection Engine bugs last week<\/a> (<a href=\"https:\/\/www.theregister.co.uk\" target=\"_blank\" rel=\"noopener noreferrer\">The Register<\/a>)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New flaws were found in Microsoft Windows 7 and Windows 8  that causes BSOD seems like the same issue we saw in Windows 95<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2885,2990,1754,1755,2927,2926,2941,2920,82,421,2928,4,11,1501,445],"class_list":["post-84323","post","type-post","status-publish","format-standard","hentry","category-security","tag-2885","tag-2990","tag-1754","tag-1755","tag-blue-screen-of-death","tag-bsod","tag-defender","tag-dos","tag-microsoft","tag-msft","tag-ntfs","tag-security","tag-vista","tag-vulnerability","tag-windows"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/84323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=84323"}],"version-history":[{"count":4,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/84323\/revisions"}],"predecessor-version":[{"id":131721,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/84323\/revisions\/131721"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=84323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=84323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=84323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}