Fw: [Full-Disclosure] whoch DCOM exploit code are they speaking about here?

From: SPAM (edwin_at_link.net.id)
Date: 09/17/03

  • Next message: Henning Brauer: "Re: [Full-Disclosure] openssh remote exploit"
    To: <full-disclosure@netsys.com>
    Date: Wed, 17 Sep 2003 10:09:08 +0700
    
    

    I think this would be the one...

    http://packetstormsecurity.nl/0309-exploits/09.16.MS03-039-exp.c

    Ed

    ----- Original Message -----
    From: "Josh Karp" <jkarp@visionael.com>
    To: <full-disclosure@lists.netsys.com>
    Sent: Wednesday, September 17, 2003 7:19 AM
    Subject: [Full-Disclosure] whoch DCOM exploit code are they speaking about
    here?

    >
    http://www.sfgate.com/cgi-bin/article.cgi?file=/news/archive/2003/09/16/nati
    > onal1842EDT0790.DTL
    >
    <http://www.sfgate.com/cgi-bin/article.cgi?file=/news/archive/2003/09/16/nat
    > ional1842EDT0790.DTL>
    >
    > Security researchers on Tuesday detected hackers distributing software to
    > break into computers using flaws announced last week in some versions of
    > Microsoft Corp.'s Windows operating system.
    > The threat from this new vulnerability -- which already has drawn stern
    > warnings from the Homeland Security Department -- is remarkably similar to
    > one that allowed the Blaster virus to infect hundreds of thousands of
    > computers last month.
    > The discovery gives fresh impetus for tens of millions of Windows users --
    > inside corporations and in their homes -- to immediately apply a free
    > repairing patch from Microsoft. Homeland Security officials have warned
    that
    > attacks could result in a "significant impact" on the operation of the
    > Internet.
    > Researchers from iDefense Inc. of Reston, Va., who found the new attack
    > software being distributed from a Chinese Web site, said it was already
    > being used to break into vulnerable computers and implant eavesdropping
    > programs. They said they expect widespread attacks similar to the Blaster
    > infection within days.
    > "It's fairly likely," said Ken Dunham, a senior iDefense analyst.
    "Certainly
    > we'll see new variants in the next few hours or days."
    > Microsoft confirmed it was studying the new attack tool.
    > Last month's Blaster infection spread just days after hackers began
    > distributing tools for breaking into Windows computers using a related
    > software flaw. That infection disrupted computers at the Federal Reserve
    in
    > Atlanta, Maryland's motor vehicle agency and the Minnesota transportation
    > department.
    > The latest Windows flaws, announced Sept. 10, were nearly identical to
    those
    > exploited by the Blaster worm. Computer users who applied an earlier patch
    > in July to protect themselves still must install the new patch from
    > Microsoft, available from its Web site.
    > Amy Carroll, a director in Microsoft's security business unit, said 63
    > percent more people have already downloaded the latest patch than
    downloaded
    > the patch for last month's similar vulnerability during the same five-day
    > period.
    > "We've continued to beat the drum, to give people better awareness,"
    Carroll
    > said. "We have seen some success."
    > The latest hacker tool was relatively polished. It gives hackers access to
    > victims' computers by creating a new account with the name "e" with a
    preset
    > password. iDefense said the tool includes options to attack two Windows
    2000
    > versions that are commonly used inside corporations.
    > The tool being distributed Tuesday did not include an option to break into
    > computers running Microsoft's latest operating systems, such as Windows XP
    > or Windows Server 2003, but iDefense said it expected such modifications
    to
    > make it more dangerous.
    >
    > On the Net:
    > Microsoft warning:
    > www.microsoft.com/security/security_bulletins/ms03-039.asp
    > <http://www.microsoft.com/security/security_bulletins/ms03-039.asp>
    > Homeland Security warning:
    > www.nipc.gov/warnings/advisories/2003/Advisory9102003.htm
    > <http://www.nipc.gov/warnings/advisories/2003/Advisory9102003.htm>
    >
    >
    >
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Henning Brauer: "Re: [Full-Disclosure] openssh remote exploit"

    Relevant Pages

    • RE: [Full-Disclosure] whoch DCOM exploit code are they speaking about here?
      ... [Full-Disclosure] whoch DCOM exploit code are they speaking about here? ... Security researchers on Tuesday detected hackers distributing software to break into computers using flaws announced last week in some versions of Microsoft Corp.'s Windows operating system. ...
      (Full-Disclosure)
    • RE: [Full-Disclosure] Insecurity in Finnish parlament (computers)
      ... > It is unlikely that all the computers have the same security ... > (both in TeliaSonera and in our parlament). ... Red herring. ...
      (Full-Disclosure)
    • Re: Basic Security Help
      ... a network is weak or no passwords followed by malicious user on your ... -- Use password policy to enforce strong passwords in the domain by enabling ... -- Be sure that computers are kept current of critical security updates from ... Windows Updates or using a SUS server to authorize and distribute security ...
      (microsoft.public.security)
    • RE: Why Easy To Use Software Is Putting You At Risk
      ... Can Easy To Use Software Also Be Secure ... Anyone who has been working with computers for a long time will have noticed ... because DNS does not configure properly or security permissions are relaxed ... guarantee that no one really knows for sure, not even Microsoft developers. ...
      (Security-Basics)
    • Re: Is complete home security possible?
      ... > If you are a gamer, some computer games will only run in administrator ... I have a clean disk image made from Norton Ghost, ... security issues to deal with to do it monthly, ... I have been using computers since 76, never had a virus on any of my ...
      (comp.security.firewalls)

    Loading