This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Hackers Jump On Windows Vuln/fix Available

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
September 16, 2004
"…Less than 24 hours after Microsoft released details of the latest vulnerability in Windows, hackers were sharing details and eager to get their hands on exploit code, said Ken Dunham, the director of malicious code research for Reston, Va.-based security intelligence provider iDefense…The most likely attack avenue…is an HTML e-mail that includes or links to a hostile .jpg image, although links to malicious Web sites or even instant messages could be used as attack vectors…Worse, even patched systems can be later turned into vulnerable computers, added Weafer, if applications with the flawed image processing .dll are later installed on made-safe PCs. "That could 'undo' the patch," said Weafer, "and makes the 'stickiness' of the more difficult than normal." In addition, Dunham concluded, not even the massive Service Pack 2 (SP2) update for Windows XP completely protects against the bug, since "other products may also need to be patched to fully protect against this vulnerability."

>>> http://www.microsoft.com/technet/security/…n/MS04-028.mspx

.
FYI…from the Internet Storm Center:

MS04-028 Proof of Concept Rumors
- http://isc.sans.org//diary.php?date=2004-09-17
Updated September 18th 2004 03:21 UTC
" At least two examples of concept code exploiting the recently announced MS04-028, Buffer Overrun in JPEG Processing (GDI+), were released in the past 24 hours. This should serve as a warning to those who are ignoring a potentially explosive vulnerability that there are individuals and groups actively at work trying to build a working exploit.

We have seen this same pattern in the past - a significant vulnerability is announced, followed in a few days by POC code that usually causes a system crash or denial of service condition, followed by a hunt to get a reliable and simple buffer overflow to work using universal stack pointer offsets. Once an attack mechanism is perfected, then it's just a matter of hours or days before worm code is launched. With the growth in popularity of the Metasploit Framework project, simple point-n-click access to vulnerable systems follows quickly, allowing anybody from script kiddies to nation states to gain unauthorized access to insecure systems.

So here we are at roughly day three. POC code is circulating. Working exploit code is probably going to find its way into the public domain within a few days or a week. Then it's up to the whims of somebody or some group to build and launch a malware attack using the newly developed exploits. Crystal ball says to look for a worm or mass-mailer by the end of September…"