Worm Takes Advantage Of Microsoft Flaw
Just as I had predicted it would happen, there are already reports that a worm exploiting the hole in the
“Server Service” has been seen in the wild. Microsoft released yesterday a critical “out-of-band” patch (MS08-067) release having known about the issue for a while.
Milw0rm, an exploit tracking Internet site has posted the exploit code required to overflow the stack. The code can be downloaded here.
Symantec is tracking an exploit “Bloodhound.Exploit.212″, via Bugtraq ID 31874 using this vulnerability, but they report it is still not widespread. Other reports points to a certain file “n2.exe” being downloaded to compromise computers, as McAfee has been tracking here.
The worm as already received several names including Gimmiv and Dropper. The guys over at Threat Expert Blog have a pretty detailed explanation of how the code works and what it does.
Both Symantec and McAfee said Friday that they had seen only a very small number of attacks based on this exploit, but Symantec says that, starting Thursday evening, they found a 25 percent jump in network scans looking for potentially vulnerable machines. That could be a sign that more attacks are coming.
It is not likely that large networks will have ports 139 and/or 445 open to the Internet and even most DSL/Cable modem router will not allow this kind of inbound traffic either, but I have no doubt this will cause a false sense of security among pseudo-system admins and as this worm evolves and becomes more sophisticated, it will transverse corporate perimeter firewall through malware and spyware and then spread within the network wreaking havoc.
My Twitts
- RT @slashdot: A5 Mystery Solved (Why Siri Won't Run On iPhone 4) http://t.co/IX0A91op 10 hours ago
- RT @patriciaaraque: Super Bowl 2012 Commercials: Watch Them All Here http://t.co/3hUrLfwu 2012/02/06
- Demasiado bueno --> RT @susana_rorra: #Madonna genial. Me hizo recordar la adolescencia #TodoUnPerformance 2012/02/06
- Awesome commercial with Clint Eastwood. #superbowl 2012/02/06
- @diegosatx conoceras a alguien en Univision Dallas.? Queremos informar sobre primarias en Dallas el proximo Domingo! 2012/02/04
- @rodolfovargas congrats 2012/02/04
Blogroll
- Blog de Economía y Finanzas
- Dameon D. Welch-Abernathy – Phoneboy
- Drew’s Marketing Minute
- Duct Tape Marketing
- Geek Dad
- Guy Kawasaki – How to Change the World
- Jeff Pulver Blog
- Kevin Kelly’s LifeStream
- Malcolm Gladwell
- Mark Cuban
- Nerd Vittles
- NovaSphere Blog
- OCS Team Blog
- Robert X. Cringely
- Seth Godin
- Small Business Trends
- The Eco-Capitalist – Tom Szaky
- UC – Joachim Farla
- WorkHappy
Sites I Visit
Spam Blocked





