Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Microsoft Braces for Worm Attack
EH-Net
May 21, 2013, 02:02:12 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Microsoft Braces for Worm Attack  (Read 5658 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: August 10, 2006, 10:30:16 PM »

Quote
A network worm attack exploiting a critical Microsoft Windows vulnerability appears inevitable, security experts warned Aug. 10.

Just days after the Redmond, Wash., software maker issued the MS06-040 bulletin with patches for a "critical" Server Service flaw, Microsoft's security response unit is bracing for the worst after exploit code that offers a blueprint for attacks began circulating on the Internet.

Even before the release of Microsoft's patch, the US-CERT (Computer Emergency Readiness Team) warned that the flaw was being used in targeted attacks and that the appearance of public exploits is a sure sign that a worm attack is imminent.

An exploit module was added to the HD Moore's Metasploit Framework that could launch attacks against all unpatched Windows 2000 systems and some versions of Windows XP.

Two penetration testing companies, Immunity and Core Security Technologies, have already created and released "reliable exploits" for the flaw, which was deemed wormable on all Windows versions, including Windows XP SP2 and Windows Server 2003 SP1.

Dave Aitel, a researcher at Immunity, said his exploits are capable of launching attacks against firewall-protected Windows XP SP2. "A worm is coming. This bug is just too easy to exploit," Aitel said in an interview with eWEEK.

For full story:
http://www.eweek.com/article2/0,1895,2002142,00.asp

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
LSOChris
Guest
« Reply #1 on: August 10, 2006, 10:48:30 PM »

didnt he say the worm would be only a DOS for XP SP2 and 2k3 SP1?

Logged
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #2 on: August 14, 2006, 02:32:31 PM »

The current bot/worm is MocBot is supposedly spreading on unpatched 2K boxes using the MS-040 vuln, but still getting conflicting reports about how serious it will be.
Logged
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #3 on: August 14, 2006, 03:00:14 PM »

I've seen about ten of these in the wild so far today. Symantec reports it as W32.Wargbot with the newest definitions and Backdoor.IRC.Bot with definitions older than August 13th. The Common Malware Enumeration number is CME-482.

So far I have only seen it attack W2K machines on networks comprised of XP and 2003 Server also. All infections appear to have been contained by antivirus, even with out of date definitions.

The payload appears to be a typcial IRC bot that listens for instructions on port 18067 although I can't confirm that being no machines have been infected.
Logged

CISSP
LSOChris
Guest
« Reply #4 on: August 14, 2006, 04:36:51 PM »

if it doesnt wreck semi current XP and 2k3 boxes i dont see how it can be "that" bad.


Logged
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #5 on: August 15, 2006, 10:40:17 AM »

Yeah, its really wierd, seeing tons of reports about, while certain vendors are saying it is a non-event. We've still only seen a few, that were non-managed systems. Old dats were detecting it as IRCbot or SDbot. Looks like it won't be that bad for most, but should serve to announce loudly which machines on your networks are unpatched/unmanaged.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.06 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.