Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Microsoft Urges Workaround as Worm Hits Unpatched DNS Flaw
EH-Net
May 19, 2013, 06:57:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Microsoft Urges Workaround as Worm Hits Unpatched DNS Flaw  (Read 4275 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: April 18, 2007, 02:10:32 PM »

Quote
With a worm exploiting the unpatched zero-day vulnerability in Microsoft's Domain Name System Service mere days after it was discovered, Microsoft on Monday urged customers to apply workarounds the company had provided in its earlier security advisory.

The W32/Delbot-AI worm, aka Nirbot or Rinbot, is infecting PCs via a vulnerability in the way the Windows DNS Server's RPC (Remote Procedure Call) interface has been implemented. Attackers are sending a crafted RPC packet to vulnerable PCs, turning them into zombie systems from which attackers can steal information and which they can control as nodes in a botnet.

As of Monday, the MSRC's Christopher Budd was still downplaying the effects of the worm, saying that the attack "does not appear widespread." Regardless, deploying workarounds provided in the security advisory to mitigate this unpatched zero-day attack should be a priority, he said. "By quickly deploying the workarounds customers can mitigate the risk of an effective attack on their networks," he writes. "Once again, we want to strongly advise customers to deploy the workarounds in their environment as soon as possible."

Microsoft in particular is urging customers to deploy a registry key workaround and to deploy the latest signatures for their security products.

Microsoft has updated its advisory three times since it was posted last week, and a spokesperson for the company told eWEEK that another update is coming via the MSRC blog sometime tonight.

The news of the worm attack comes only a week after Microsoft issued patches for critical vulnerabilities on its monthly Patch Tuesday. On top of those patches, subsequent reports of bugs in Microsoft Office appeared, and Microsoft's security team have also been busy investigating attacks aimed at Vista's OEM BIOS activation feature.

"The computer underground appear to be revelling in waiting until Microsoft has released its monthly batch of patches, before unleashing their latest attacks," said Graham Cluley, senior technology consultant for Sophos, in a post. "It's not just businesses who are being affected by this, but Microsoft will not be enjoying having the security of their software brought into question again."

As for the timing of a patch, a Microsoft spokesperson couldn't give eWEEK a timeline. The MSRC's Budd said in his Monday post that teams are working "around the clock" on the update and are monitoring the situation along with the company's MSRA partners.

"As soon as we have any new information, we'll update you through the advisory and the MSRC weblog," he wrote.

For original story:
http://securitywatch.eweek.com/exploits_and_attacks/microsoft_urges_workaround_as_worm_hits_unpatched_dns_flaw.html

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.07 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.