Re: RPC/DCOM Worm Released

From: Alessandro Perilli (peris_at_tiscali.it)
Date: 07/30/03


Date: Wed, 30 Jul 2003 15:36:55 +0200


On 30 Jul 2003 02:09:24 -0700, Paul Lynch wrote:

> Hello,
>
> This is a quick heads-up to let you know that there have been
> 'sightings' of a new worm which seeks to exploit the latest
> vulnerability in all versions of Windows.
>
> More details here :
>
> http://grc.com/default.htm
> http://vil.nai.com/vil/content/v_100516.htm
>
> Patch available here :
>
> http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
>
> Regards,
>
> Paul Lynch
> MCSE

I expect a second, more aggressive worm after this one since every day a
more-targets RPC exploit is released: first one had 3 targets, second one
5, then a 18 targets exploit appeared, and now I can see a 44 targets
exploit available around (Chinese, Japanese, Korean, English, German and
Mexican targets are vulnerable at now).

Also security research group unveiled this vulnerability reports they
founded a universal address that works with against win2k/XP machines,
without looking at SP level.

-- 
Alessandro Perilli
Security Consultant / Trainer
MCT - MCSE 2000 SECURITY - LINUX+
CCSI - CCSE 2000 - CCSE+ NG
CCNA - CIWP - CIWSA - CCA XP
SECURITY+ 


Relevant Pages

  • RE: ISS Security Alert: Resurgence of "Code Red" Worm Derivatives
    ... Subject: ISS Security Alert: Resurgence of "Code Red" Worm Derivatives ... This vulnerability was ...
    (Focus-IDS)
  • Re: MSHTML.dll/MSN Messenger demonstration site
    ... The site does do things very similar to what that worm does, ... NTBugtraq may contain harmful code, code that your AV picks up as ... Go Beyond PARTIAL Security: FREE White Paper ... perimeter with the most current and most complete PROACTIVE Vulnerability ...
    (NT-Bugtraq)
  • Spammers Jump on Latest MS Hole
    ... Security companies were gearing up for war last week, ... dire predictions of massive worm outbreaks from security ... in Windows' Server Service, a Windows component that provides support ... "I think when you look at the nature of the vulnerability, ...
    (comp.dcom.telecom)
  • A Very Dangerous Worm in Windows Metafile Images (WMF)
    ... a very dangerous computer worm was released on the ... It is carried on Windows Metafile images and automatically ... Going back to the wmf vulnerability itself, ... poweruser' types, developers with a casual interest in security, ...
    (sci.electronics.design)
  • FW: Preliminary Lessons and Thoughts
    ... When we respond by inefficient security, ... The network is not likely to be high on his list of targets. ... infrastructure technology in the world that puts controls intended for the ... TREND MICRO SCANMAIL FOR EXCHANGE 2000 -- SECOND to NONE ...
    (NT-Bugtraq)