Re: [NEWS] Hacker code could unleash Windows worm

From: The Other Guy (nospam_at_this.addy)
Date: 07/28/03

  • Next message: Bit Twister: "Re: [NEWS] Hacker code could unleash Windows worm"
    Date: Mon, 28 Jul 2003 02:21:39 GMT
    
    

    On Mon, 28 Jul 2003 02:00:49 GMT, The Other Guy responded to a post
    from alun@texis.com (Alun Jones [MS MVP]) who wrote in
    alt.computer.security:

    >In article <0ob8ivg78ncq1gcdveqtckkpucbt0h4d6s@4ax.com>, The Other Guy
    ><nospam@this.addy> wrote:
    >>
    >>http://news.com.com/2100-1002_3-5055759.html
    >>
    >>A hacker group released code designed to exploit a widespread Windows
    >>flaw, paving the way for a major worm attack as soon as this weekend,
    >>security researchers warned.
    >
    >Just for information's sakes, the hole for this exploit has been patched,
    >and anything close to capable of being called a firewall will block the
    >attack.
    >
    >Yet another call to the world to download patches, update your machines, and
    >make sure you're behind a firewall. Wouldn't it be nice if the CNet article
    >bothered to mention this simple security measure? Honestly, it's as if they
    >_want_ people to panic and scream curses.
    >
    >Alun.

    Good point, Alun, about the patches, and that was my main intention in
    posting this news release was to give a subtle reminder to the readers
    in these N/Gs that if they haven't patched they may be in trouble
    soon. Also why I included a link to the previous public news release
    (http://news.com.com/2100-1009-1026420.html?tag=nl) dated July 15th..

    In security portals it has been discussed a lot in the last couple of
    weeks (Buffer Overrun In RPC Interface Could Allow Code Execution);
    indeed, http://isc.incidents.org/ has been giving a "Last Chance" to
    patch "to avoid becoming a victim to RPC exploits in the works now.
    Block" warning for several days.

    Exploit reported by http://lsd-pl.net/special.html

    Patch available at
    http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-026.asp

    And CNN news cause the public to act hysterical as a result of its
    sensational reporting, i just can't believe it </sarcasm> ;-)

    Cheers,
    TOG

    -- 
    ./configure --prefix=~/zyterion
    Not this guy or that guy, The Other Guy.
    "If you're not thoroughly confused by now, then you just
    don't understand the situation."
    

  • Next message: Bit Twister: "Re: [NEWS] Hacker code could unleash Windows worm"

    Relevant Pages

    • Re: [NEWS] Hacker code could unleash Windows worm
      ... >>A hacker group released code designed to exploit a widespread Windows ... >>security researchers warned. ... Good point, Alun, about the patches, and that was my main intention in ... Also why I included a link to the previous public news release ...
      (comp.security.misc)
    • Re: How to Maintain an IIS Server?
      ... >>> I looked at the Microsoft Security Website. ... >> before a firewall and antivirus have been installed]. ... >> new patches that are missing, ...
      (microsoft.public.inetserver.iis.security)
    • RE: Patching
      ... There seems to be at least 5 or 6 new vulnerabilities released on ... As information security people, ... at those patches you need for what you do have running. ... network analyzers. ...
      (Security-Basics)
    • Re: Anyone know why the Alpha market is so so quiet?
      ... this with all of the Windows security patches. ... Because if those systems where running Linux - how many security ... With 5-20 Linux (and Windows) security patches being released each ... have they told you was behind their decision to turf VMS out? ...
      (comp.os.vms)
    • Re: How to Maintain an IIS Server?
      ... > [for MS MBSA Baseline Security Analyzer] ... Get a firewall or two as well, ... >>> new patches that are missing, ... >>> software installed on your computer, especially Microsoft Windows, ...
      (microsoft.public.inetserver.iis.security)