AKB Forums

Go Back   AKB Forums > Technical sections > Software Security
Home Register Blogs FAQ Members List Calendar Downloads Arcade Mark Forums Read

Software Security Discussing software security algorithms, tricks, vulnerabilities

Troubles when posting message? Click here! :: Проблемы с отправлением сообщения? Нажмите сюда!

Reply
 
LinkBack Thread Tools Display Modes
Old Oct 19, 2005, 16:27   #1
Administrator
 
acid's Avatar
 
Join Date: Sep 2001
Location: South Korea, Gumi
Posts: 7,189
Blog Entries: 15
Rep Power: 10
Reputation: 313
Exploit code raises Windows worm alarm

Computer code has already been written to take advantage of Windows flaws that were disclosed Tuesday, a sign that a worm attack could be near.

Exploit code exists for four of the 14 vulnerabilities for which Microsoft provided fixes this week, experts said Thursday. One of the exploits was written for a flaw which Microsoft tagged as "critical." The bug lies in a Windows component for transaction processing called the Microsoft Distributed Transaction Coordinator, or MSDTC.

"When we start to see exploits surfacing, we know there will shortly be malicious code," said Alfred Huger, a senior director at Symantec Security Response. "We expect at least the MSDTC vulnerability to be used in a worm in the short term."

After Microsoft released vulnerability information, the exploit code was written within 24 hours, noticeably quicker than the average time it takes for an exploit to appear, Huger said. "Over the last two years on average it has been between four and 5.8 days for an exploit to come out after a vulnerability was released," he said.

When Microsoft released its patches on Tuesday, experts had already warned that the MSDTC flaw could spawn an attack similar to the Zotob worm that wreaked havoc two months ago. Microsoft urged users of older operating systems, specifically Windows 2000 and Windows XP before Service Pack 2, to prioritize the update that fixes the flaw, which is addressed in security bulletin MS05-051.

The MSDTC exploit isn't publicly available, but experts predict a public exploit is not far off. The code was created by security vendor Immunity for users of its penetration testing product. Immunity also crafted exploits for a flaw that involves plug-and-play in Windows (MS05-047) and a bug in a component that supports Novell NetWare networks (MS05-046).

Furthermore, code that exploits a flaw in Microsoft's Windows FTP client (MS05-045) is available publicly on the Internet, said Michael Sutton, director at security intelligence company iDefense, a part of VeriSign.

"Patching is very urgent," Sutton said. "We expect public exploit code to become available, especially for the MSDTC issue."



Microsoft is aware of Immunity's exploit code, but has not seen any attacks that use the code, a company representative said. "Microsoft is actively monitoring this situation," the representative said in an e-mailed statement.

Symantec's Huger predicts a worm exploiting the MSDTC flaw will surface in the next several days. It is unknown how hard the worm will hit. "There are so many variables involved with that, it is tough to say," he said.

http://news.com.com/Exploit+code+raises+Windows+worm+alarm/2100-1002_3-5894971.html?tag=nl
__________________
Chat with acid


acid is offline   Reply With Quote Quote selected
Old Oct 19, 2005, 18:17   #2
Banned
 
Forever Child's Avatar
 
Join Date: Oct 2001
Location: ...осень колибри
Posts: 7,493
Rep Power: 0
Reputation: 10
Send a message via ICQ to Forever Child Send a message via AIM to Forever Child Send a message via Yahoo to Forever Child
будем молиться.
Forever Child is offline   Reply With Quote Quote selected
Old Oct 19, 2005, 18:25   #3
Banned
 
Forever Child's Avatar
 
Join Date: Oct 2001
Location: ...осень колибри
Posts: 7,493
Rep Power: 0
Reputation: 10
Send a message via ICQ to Forever Child Send a message via AIM to Forever Child Send a message via Yahoo to Forever Child
только что проверил свой antivir (www.free-av.com) на предмет апдейта. кажется они уже среагировали.

Last edited by Forever Child : Feb 11, 2006 at 21:04.
Forever Child is offline   Reply With Quote Quote selected
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Download Free Ebooks (Computers, Physics, Math and more) acid TWARM 221 Sep 12, 2008 02:10
Windows LongHorn - New Generation of M$ Fiddlesticks!!! Hrach_Techie TWARM 0 Sep 13, 2004 14:36
Украден и опубликован исходный код Windows NT 4 и Windows 2000 acid Software Security 10 Feb 16, 2004 06:52
Browser (User Agent) Usage Statistics acid Web Development 4 Jan 12, 2004 08:26
Решение для избавления от активации на всех версиях Windows XP и Windows .NET acid Software Security 2 Oct 4, 2002 21:40


All times are GMT. The time now is 02:54.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
This board was founded on September 29, 2001
Powered by Viper Internet

Affordable Web Hosting | ParevNet

Buy text link