This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS06-066, MS06-067, MS06-070 exploits out

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700027
November 16, 2006
"…Both proof-of-concept exploit code and a public exploit have popped up for the bug fixed in MS06-070, a security update that patched Windows 2000's and Windows XP's Workstation Service, a routing service used by the operating system to determine if file or print requests originate locally or remotely. Microsoft pegged MS06-070 with its "critical" ranking, the highest threat warning it assigns updates. "We've confirmed exploit code from two different sources," said Amol Sarwate, the manager of Qualys' vulnerability lab. "The window [of time] to exploit is definitely shrinking." It's become common for exploits to crop up within days of Microsoft's monthly patch release. The trend has become routine enough to get its own moniker: "Exploit Wednesday"… Blocking ports 139 and 445, one of the workarounds Microsoft offered Tuesday in the MS06-070 bulletin, isn't really feasible, said Sarwarte. "There are maybe 15 different services that won't work if you close those ports," he said. Symantec pegged another of the half-dozen updates – the one spelled out in the MS06-066 bulletin – as now sporting an exploit against the disclosed bug…"

:ph34r: :ph34r:
FYI…

Malicious Website / Malicious Code: MS06-067
- http://www.websense.com/securitylabs/alert…php?AlertID=698
November 14, 2006
"Websense® Security Labs™ received proof of concept code for a vulnerability in the "DirectAnimation ActiveX Control" in September 2006. Since that time our miners have been searching for sites that are exploiting this vulnerability. Multiple sites were discovered to be actively exploiting this in the wild. The majority of these sites have been installing a variant of the HaxDoor backdoor/keylogger…"

(Screenshots available at the URL above.)

> http://www.microsoft.com/technet/security/…n/ms06-067.mspx

:ph34r: