Re: [Full-disclosure] No one else seeing the new MS05-039 worm yet?

From: Peter Ferrie (pferrie_at_symantec.com)
Date: 08/30/05

  • Next message: fd_at_ew.nsci.us: "Re: [Full-disclosure] No one else seeing the new MS05-039 worm yet?"
    To: full-disclosure@lists.grok.org.uk
    Date: Tue, 30 Aug 2005 14:14:41 -0700
    
    

    ...

    >Lastly they don't point out that "worm" propagation based on the
    >PnP vulnerability only occurs on the Win2K boxes. Win2K3 and
    >WinXP require some user/machine action to exploit the
    >vulnerability, and the malware can't infect those boxes
    >independently.

    It's not quite like that.
    XP pre SP2 is vulnerable to attack. They will most likely
    crash because of a wrong address, but they can be reached.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: fd_at_ew.nsci.us: "Re: [Full-disclosure] No one else seeing the new MS05-039 worm yet?"

    Relevant Pages

    • Re: [Full-Disclosure] YEY AGAIN Automatic remote compromise of InternetExplorer Service Pack 2 XP SP
      ... YEY AGAIN Automatic remote compromise of ... InternetExplorer Service Pack 2 XP SP2 ... > Microsoft Internet Explorer XP SP2 Fully Automated Remote Compromise ... > vulnerability in itself, but rather it is uses multiple known holes in SP2 ...
      (Full-Disclosure)
    • Re: The whole Apple can Run Windows thing...
      ... case that SP2 has been out for "a long time now", ... you're referring to was the RPC vulnerability - it was fixed with a couple ... "analysts" who discover security holes who are the smart ones - and from ... no longer allowed direct access to system resources - instead (in the case ...
      (rec.photo.digital.slr-systems)
    • RE: [Full-Disclosure] YEY AGAIN Automatic remote compromise ofInternetExplorer Service Pack 2 XP SP2
      ... YEY AGAIN Automatic remote compromise ... ofInternetExplorer Service Pack 2 XP SP2 ... > vulnerability in itself, but rather it is uses multiple known holes in SP2 ... > Vulnerability and Help ActiveX Control Related Topics Cross Site Scripting ...
      (Full-Disclosure)
    • Re: Q323759 question
      ... >Outlook Express with the Preview Pane active, to infect ... vulnerability is separate ... >Open Outlook Express, and go to Help, About, and be sure ... >Temporary Internet Files are one, ...
      (microsoft.public.security)
    • Re: HOWTO: How to remove VX2 spyware (the latest and worst versions)
      ... >> Actually SP2 could have little to do with it. ... | SECURITY VULNERABILITY FIXES WERE ALLOWED. ... The adware/spyware you indicated are not installed via an OS vulnerability. ... Your friend has what's called contributory negligence. ...
      (microsoft.public.windowsxp.general)