P
PA Bear
Guest
Re: Vista x32 IE7 SSL Security Problem
Forwarded to Vista Security newsgroup via crosspost as a convenience to the
OP.
What anti-virus or "internet security" suite are you running?
=> Does this behavior persist if you start IE7 in No Add-ons mode? To start
IE7 in No Add-ons mode:
1. Right-click on the blue IE desktop icon and select Start without Add-ons;
2. Start > (All) Programs > Accessories > System Tools > Internet Explorer
(No add-ons).
More:
Troubleshooting and Internet Explorer’s (No Add-ons) Mode:
http://blogs.msdn.com/ie/archive/2006/07/25/678113.aspx
=> Does the problem persist if you Reset IE7 Settings (RIES)?
http://support.microsoft.com/kb/923737 <= Read before using!
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE, OE, Security, Shell/User)
AumHa VSOP & Admin; DTS-L.org
Bathrone wrote:
> Sadly I have not been able to progress this further.
>
> I called Microsoft for support, but they wanted to charge me for it and I
> don't use credit cards. When I explained this was a bug, they retorted
> with
> hints at malware and if indeed it was a bug I would be refunded. Which is
> catch22 when I don't use credit cards. My antimalare product is onecare,
> which since it is not detecting any malware could be considered a bug in
> onecare. Though I doubt it being malware since Kaspersky online scanner
> doesn't detect it, not does Adaware, superantispyware etcet.
>
> I now have a pattern for problem number 2. I open IE and confirm only TLS
> is
> enabled in advanced user preferences. I leave IE closed for a few hours -
> open IE again and immediately goto advanced user preferences and I see SSL
> v2, SSL v3 and TLS all enabled despite my user preference earlier. SSL2 is
> a
> security problem as well.
>
> I don't understand why I'm not getting any help from Microsoft on this
> when
> clearly there is a serious security problem with IE7 on Vista. Even if it
> is
> malware two issues for Microsoft is why oncecare isn't detecting it (and
> other leading anti-malware products) and secondly by what exploit did it
> get
> installed under a well configured Vista install with what I like to think
> is
> a reasonably savvy admin/user on the system.
>
> Asking for support outside of Microsoft has not contributed to the problem
> because I think it will take someone with expert knowledge of windows
> internals.
<paste>
> I'm on Vista x32 IE7 fully patched to current windows update and the two
> performance and reliability hotfixes. There is three specific problems
>
> 1. I can't establish a 256 bit AES SSL session.
>
> 2. Advanced user preference settings for SSL3 and SSL2 being disabled are
> being re-enabled by something. Even if I disable them again if I apply,
> close IE and wait awhile they will be renabled again if I check the
> advanced
> settings.
>
> 3. I am getting strange recurring error and warning level events in the
> windows system log about SSL.
>
> Details:
>
> Using Firefox alpha 7 I can easily goto
> https://www.fortify.net/sslcheck.html and see I'm running
> DHE-RSA-AES256-SHA. In my IE7 install SSL negotiates AES128-SHA
>
> I have no explanation as to how or why SSL3 and SSL2 are being enabled and
> overwriting user peference.
>
> The details of the system events are:
>
> E1. An error occured while using SSL configuration for socket address
> 192.168.1.2:6331. The error status code is
>
> contained within the returned data. ID: 15021 Source: HTTPEvent
>
> E2. An error occured while using SSL configuration for socket address
> 255.255.255.255:6331. The error status code
>
> is contained within the returned data. ID: 15021 Source: HTTPEvent
>
> W1. SSL Certificate Settings deleted for Port : 192.168.1.2:6331 . ID:
> 15300 Source: HTTPEvent
>
> W2. SSL Certificate Settings created by an admin process for Port :
> 192.168.1.2:6331 . ID: 15301 Source: HTTPEvent
>
> W3. SSL Certificate Settings deleted for Port : 255.255.255.255:6331 .ID:
> 15300 Source: HTTPEvent
>
> W4. SSL Certificate Settings created by an admin process for Port :
> 255.255.255.255:6331 .ID: 15301 Source:
>
> HTTPEvent
>
> W5. SSL Certificate Settings deleted for Port : 255.255.255.255:6331
> .15300
> Source: HTTPEvent
>
> W5. SSL Certificate Settings created by an admin process for Port :
> 255.255.255.255:6331 .ID: 15301 Source:
>
> HTTPEvent
>
> I do not know what so called admin process is doing this. It occurs on
> each
> reboot on my system. The MS online event search facility provides no
> explanation of these events.
>
> My antimalware product reports no problems. The Kaspersky online scanner
> reports no problems. I have gone though the browser helper objects and
> found
> nothing unusual. I have also gone through my running processes and found
> nothing unusual. Same with startup processes.
>
> I am determined to get to the bottom of this problem and would greatly
> appreciate expert advice in helping to diagnose this further.
Forwarded to Vista Security newsgroup via crosspost as a convenience to the
OP.
What anti-virus or "internet security" suite are you running?
=> Does this behavior persist if you start IE7 in No Add-ons mode? To start
IE7 in No Add-ons mode:
1. Right-click on the blue IE desktop icon and select Start without Add-ons;
2. Start > (All) Programs > Accessories > System Tools > Internet Explorer
(No add-ons).
More:
Troubleshooting and Internet Explorer’s (No Add-ons) Mode:
http://blogs.msdn.com/ie/archive/2006/07/25/678113.aspx
=> Does the problem persist if you Reset IE7 Settings (RIES)?
http://support.microsoft.com/kb/923737 <= Read before using!
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE, OE, Security, Shell/User)
AumHa VSOP & Admin; DTS-L.org
Bathrone wrote:
> Sadly I have not been able to progress this further.
>
> I called Microsoft for support, but they wanted to charge me for it and I
> don't use credit cards. When I explained this was a bug, they retorted
> with
> hints at malware and if indeed it was a bug I would be refunded. Which is
> catch22 when I don't use credit cards. My antimalare product is onecare,
> which since it is not detecting any malware could be considered a bug in
> onecare. Though I doubt it being malware since Kaspersky online scanner
> doesn't detect it, not does Adaware, superantispyware etcet.
>
> I now have a pattern for problem number 2. I open IE and confirm only TLS
> is
> enabled in advanced user preferences. I leave IE closed for a few hours -
> open IE again and immediately goto advanced user preferences and I see SSL
> v2, SSL v3 and TLS all enabled despite my user preference earlier. SSL2 is
> a
> security problem as well.
>
> I don't understand why I'm not getting any help from Microsoft on this
> when
> clearly there is a serious security problem with IE7 on Vista. Even if it
> is
> malware two issues for Microsoft is why oncecare isn't detecting it (and
> other leading anti-malware products) and secondly by what exploit did it
> get
> installed under a well configured Vista install with what I like to think
> is
> a reasonably savvy admin/user on the system.
>
> Asking for support outside of Microsoft has not contributed to the problem
> because I think it will take someone with expert knowledge of windows
> internals.
<paste>
> I'm on Vista x32 IE7 fully patched to current windows update and the two
> performance and reliability hotfixes. There is three specific problems
>
> 1. I can't establish a 256 bit AES SSL session.
>
> 2. Advanced user preference settings for SSL3 and SSL2 being disabled are
> being re-enabled by something. Even if I disable them again if I apply,
> close IE and wait awhile they will be renabled again if I check the
> advanced
> settings.
>
> 3. I am getting strange recurring error and warning level events in the
> windows system log about SSL.
>
> Details:
>
> Using Firefox alpha 7 I can easily goto
> https://www.fortify.net/sslcheck.html and see I'm running
> DHE-RSA-AES256-SHA. In my IE7 install SSL negotiates AES128-SHA
>
> I have no explanation as to how or why SSL3 and SSL2 are being enabled and
> overwriting user peference.
>
> The details of the system events are:
>
> E1. An error occured while using SSL configuration for socket address
> 192.168.1.2:6331. The error status code is
>
> contained within the returned data. ID: 15021 Source: HTTPEvent
>
> E2. An error occured while using SSL configuration for socket address
> 255.255.255.255:6331. The error status code
>
> is contained within the returned data. ID: 15021 Source: HTTPEvent
>
> W1. SSL Certificate Settings deleted for Port : 192.168.1.2:6331 . ID:
> 15300 Source: HTTPEvent
>
> W2. SSL Certificate Settings created by an admin process for Port :
> 192.168.1.2:6331 . ID: 15301 Source: HTTPEvent
>
> W3. SSL Certificate Settings deleted for Port : 255.255.255.255:6331 .ID:
> 15300 Source: HTTPEvent
>
> W4. SSL Certificate Settings created by an admin process for Port :
> 255.255.255.255:6331 .ID: 15301 Source:
>
> HTTPEvent
>
> W5. SSL Certificate Settings deleted for Port : 255.255.255.255:6331
> .15300
> Source: HTTPEvent
>
> W5. SSL Certificate Settings created by an admin process for Port :
> 255.255.255.255:6331 .ID: 15301 Source:
>
> HTTPEvent
>
> I do not know what so called admin process is doing this. It occurs on
> each
> reboot on my system. The MS online event search facility provides no
> explanation of these events.
>
> My antimalware product reports no problems. The Kaspersky online scanner
> reports no problems. I have gone though the browser helper objects and
> found
> nothing unusual. I have also gone through my running processes and found
> nothing unusual. Same with startup processes.
>
> I am determined to get to the bottom of this problem and would greatly
> appreciate expert advice in helping to diagnose this further.