MCSE World
Everything you need for your Microsoft certifications...MCITP, MCTS, MCSE, Architect, Master and more!
 

Welcome to the MCSE World forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

1. We will remove new users that have 0 posts after 1 Month - so make sure you post a RELEVANT TO THE FORUM POST as soon as possible. Additionally after 18 months users with less than 5 posts will be removed.

2. The private message system is only available to members that have placed more than 3 valid posts - this is to prevent PM spamming.

3. The "Infocenter " along the top menu includes Book Reviews etc and is located in a separate section to the "General Forums" area.

- Administrator

Go Back   MCSE World > Windows Items and Issues > Windows Server 2003
Login Register Site Rules Home Today's Posts Forums:  Home | List Donate Arcade InfoCenter Search Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
Old 02-17-2004, 04:32 PM   #1
QOD
Moderator
Quantum.Orbital.Dynamics
 
QOD's Avatar
 
Join Date: Sep 2003
Location: Ohio
Posts: 2,483
Thanks: 0
Thanked 1 Time in 1 Post
Exploit code for Microsoft vulnerability circulating

source http://gcn.com/vol1_no1/daily-updates/24946-1.html

Quote:
Exploit code for Microsoft vulnerability circulating

By William Jackson
GCN Staff

Security researchers say code designed to exploit a recently announced critical vulnerability in Microsoft operating systems now is widespread on the Internet.

The code crashes targeted computers by exploiting a flaw in Microsoft’s Abstract Syntax Notation 1 Library in Windows NT, 2000 and XP. The exploit code was discovered Saturday, four days after the vulnerability and a patch to correct it was announced by Microsoft.

“The exploit we discovered is fully functional and does cause targeted computers to crash,” said Ken Dunham, director of malicious code for iDefense Inc. of Reston, Va. “The widespread distribution of this code has significantly increased the threat level for ASN.1.”

The code is available on several discussion groups and Web sites.

Dunham said there have been reports of denial-of-service attacks against specific targets using this exploit, but the attacks are not yet widespread.

“It may be a few days before we see anything beyond a DOD attack,” he said. “Several attackers are actively working on an ASN.1 exploit to spread Trojans and ‘bots. One attacker has expressed an interest in creating a worm that will ‘take down the Internet.’”

Dunham said the malicious actors are capable of “weaponizing” the exploit, but have so far had little success in their tests.

The code causes the Microsoft Local Security Authority Subsystem process, LSASS.exe, to crash. It can be sent via Server Message Blocks or NetBIOS file sharing protocols to computers listening on ports 445 or 139. Blocking untrusted access to these ports and installing the Microsoft patch will protect against this exploit.

“Most large companies have already started to roll out patches,” Dunham said. “It will take at least five to seven days for most to completely patch computers, and that is not including a comprehensive audit.”

That window could leave many computers vulnerable.

In other malicious-code news, Symantec Corp. of Cupertino, Calif., has raised the security level for the new Welchia worm because of increasing numbers of infections.

Welchia, also known as Nachi, first appeared last August in the wake of the MSBlaster worm. It automatically patched against the vulnerability exploited by Blaster. The new version, Welchia.b, appears to remove the MyDoom a and b worms from infected machines. Once installed on a machine, it tries successively to exploit three vulnerabilities against a random IP address.

(Posted 12:54 p.m. and updated 4:00 p.m.)
__________________
Too many QODs, very few brain cells.
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump



Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright © 2003-2009, MCSE World.