0.0
0.0
dazhizhuq2
暱稱: dazhizhuq2
性別: 男
國家: 中國內地
地區: 其他地區
«‹ October 2026 ›»
SMTWTFS
123
45678910
11121314151617
18192021222324
25262728293031
最新文章
•中文名称
•时
•影响系统
•病毒行为
•以担任主
文章分類
•全部 (71)
訪客留言
最近三個月尚無任何留言
每月文章
日誌訂閱
尚未訂閱任何日誌
好友名單
尚無任何好友
網站連結
尚無任何連結
最近訪客
最近沒有訪客
日誌統計
文章總數: 71
留言總數: 10
今日人氣: 7
累積人氣: 3659
站內搜尋
RSS 訂閱
RSS Feed
2010 年 5 月 24 日  星期一   晴天


Microsoft RPC exploit 分類: 未分類

Microsoft RPC exploit could be a packaged deal

While Microsoft has labeled Thursday's emergency patch MS08-067 as "critical" and provided a rareout-of-cycle fix because its exploit could easily be used as worm on a compromised network, one security researcher doesn't th nike air max 90 white ink it will happen that way.

"It's likely we're going to see this packaged with some other attack." said Ben Greenbaum, senior research manager at Symantec. "A Web-based attack nike air max 90 current , for example. We're looking out for are exploits of this being bundled with client-side exploits or Trojans so that the worm can get past corporate firewalls and get behind that fir huarache low ewall into the internal network."

Comparisons have been made to Zotob, an RPC worm that spread like wildfire in 2005. Remote Procedure Calls (RPC) allows programmers to run code e air max 2010 ither locally or remotely; a flaw within them is ideal for creating a worm.

"The potential is certainly there," Greenbaum said, adding that modern day attackers are "looking to create as much revenue for themse custom nike air max lves as possible, and part of that equation means avoiding detection. What we're likely to see is that this will be added to a wide variety of attack tool kits already available."

"It's possible--but it' nike air max huarache s not likely--that we'll end up seeing a purpose-built worm that only exploits this one vulnerability," he said.

Since the patch came out Thursday morning, Symantec has s nike air max 2010 een increased scanning on ports 139 and 445, ports that exploits of MS08-067 would use.

There are some mitigating factors. Most firewalls, with default settings in place, should not allow an exploit of thi jordan huarache s penetrate that firewall, he said. However, home networks with File and Printer Sharing could fall victim to a bundled attack using this exploit.

The greatest danger is to sys air max shoes tems running Windows XP and Windows 2000; Microsoft has ranked the patch as critical for these systems. On Windows Vista, Windows Server 2008, or Windows 7 pre-Beta, if the firewall is disabled, and File and Printer s men huarache haring enabled, an anonymous user could use this exploit to connect but would do so only at the lowest possible integrity setting, which would prevent successful exploitation, Greenbaum s buy air max shoes aid. Microsoft has rated the patch only as important for those operating systems.

 

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to sh 

black huarache

 are his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your ques 

air max 360

 tions and comments. Topics: News, Vulnerabilities & attacks Tags: security, Microsoft, MS08-067, Ben Greenbaum, Symantec, File and Printer Sharing, RPC, exploit, worm, ports 139, port 445 Share: Digg Del.icio.us Reddit Facebook Twitter






訪客留言 (返回 dazhizhuq2 的日誌)

訪客名稱:
電郵地址: (不會公開)
驗證碼:  按此更新驗證碼 (如看不清楚驗證碼請點擊圖片刷新)
俏俏話: (必需 登入 後才能使用此功能)
[ 開啟多功能編輯器 ]