Feb 08,2012 - 12:38 am


Newsapp advertise

* Top 5 Downloads pick

Sponsors

Pool

  • Which Antivirus Software Do you Use?
  • View Topic

Follow me

Folow me on Twitter

NewsRSS.png

gbutton.png

Follow me on Facebook

Newsapp Friends

* Popular Topics

* Recent

Re: KMPlayer 3.1.0.0 Final - Download
by tortugahi | 09. January 2012., 23:48:04
...
Avira AntiVir Personal 12.0.0.885 - Download
by amko_sa | 09. January 2012., 11:22:15
...
Picasa 3.9.0 Build 135.78 - Download
by amko_sa | 09. January 2012., 11:18:55
...
Re: SharePoint
by amko_sa | 04. January 2012., 11:41:35
...
Re: Avira AntiVir Personal 12.0.0.885 - Download
by Samker | 16. December 2011., 20:16:11
...

Stats

Forum Stats Forum Stats

2484 Posts in 2258 Topics by 368 Members. Latest Member: t.rabbit313
View the most recent posts on the forum.

Users Online Users Online

272 Guests, 0 Users (89 Spiders)

Users active in past 20 minutes:
MSN (2), Google, Baidu (86)

Most Online Today: 362. Most Online Ever: 994 (24. August 2011., 07:25:32)

Newsapp Search


Author Topic: Unpatched Windows XP-related hole exploited in attacks  (Read 560 times)

  • Administrator
  • Newsapp Member
  • *
    • Posts: 3269
    • Reputation: 71
    • Press any key to continue or any other key to quit
    • Newsapp IT support Portal
Unpatched Windows XP-related hole exploited in attacks
« on: 16. June 2010., 20:01:14 »


Attacks target Windows XP users

A critical Windows remote code execution vulnerability disclosed last week is already being exploited in the wild. Security companies warn that attackers are luring unsuspecting users onto malicious Web pages that leverage the flaw to install malware on their computers.

 
Last Thursday, Tavis Ormandy, an information security engineer at Google revealed details about a previously unknown vulnerability in the Windows Help and Support Center. Considering that his disclosure included fully working exploitation code and that Microsoft was only given five days in advance to patch the bug, many people in the information security community accused Ormandy of acting irresponsibly.

"Today, we got the first pro-active detection (Sus/HcpExpl-A) on malware that is spreading via a compromised website. This malware downloads and executes an additional malicious component (Troj/Drop-FS) on the victim’s computer, by exploiting this vulnerability," Donato Ferrante, a security researcher at Sophos, announced yesterday. "In my opinion publishing exploit code was utterly irresponsible behaviour, and I was worried that having such information floating around the internet would make it easy for cybercriminals to take advantage," Graham Cluley, the company's senior technology consultant, commented.

Microsoft confirmed the attacks via its official advisory on the issue, but it describes them as "targeted  and limited." Additionally, according to the company, these attacks only target Windows XP, despite the vulnerability affecting both Windows XP and Windows 2003 operating systems.

Meanwhile, security researchers from antivirus vendor Trend Micro have also intercepted some drive-by download attacks exploiting the unpatched flaw. After looking into them, Joseph Cepe, a threat analyst at the company, concluded that there were two distinct methods of delivering the malware.

The first requires tricking users into clicking on a prompt to initiate the exploitation, which downloads a trojan on their computers. This trojan then downloads another trojan, which in turn downloads additional malware, including scareware.

The second approach, which according to the researcher, is stealthier, uses a page which initiates Windows Media Player and pushes an .ASX (Advanced Stream Redirector) file to it. These are XML files, similar to playlists and can contain references to other addresses. In this case, the URL it points to is currently inactive.

Microsoft has released an automated "Fix it" tool to temporarily address the issue, until a permanent patch is tested and delivered to users. The tool basically prevents the use of hcp:// links, which this exploit requires to work, system wide. However, this will also break legit functionality using such URLs.

(SP)


Tags:
 

Chat

Refresh History
  • uday: send me heriens14.1 link
    26. November 2011., 08:27:19
  • uday: pl send me pm link
    26. November 2011., 08:07:19
  • amko_sa: Kysior, I was send download links to your PM ;)
    30. October 2011., 14:02:30
  • kysior: Please PM me link for Hirens 15.0. Thanks
    29. October 2011., 19:59:48
  • Opticprism: THANKS amko_sa I got the PM.
    26. August 2011., 07:44:22
  • normandg: I have not received a PM.
    24. August 2011., 21:34:55
  • amko_sa: I am write Hiren 14.1 links for members on Hirens BootCD 14.1 topic. (second page)
    24. August 2011., 19:23:52
  • amko_sa: I am sent all the PM with Hiren BootCD 14.1 links :)
    24. August 2011., 19:21:59
  • karthicks89: Please PM me link for Hirens 14.1. Thank you
    24. August 2011., 15:01:28
  • amko_sa: I have a links  ;D
    24. August 2011., 11:51:37
  • normandg: Are you unable to find it too?  Is that why you have not sent anyone the link?
    23. August 2011., 22:58:13
  • boki7777: Please PM me link for Hirens 14.1. Thank you
    23. August 2011., 22:00:53
  • Allaraine: Could you please send me the link when it is ready? Thank you. Hiren's Boot CD 14.1.
    23. August 2011., 18:06:14
  • angel1610: Thanks a lot amko_sa
    23. August 2011., 17:18:00
  • Opticprism: Appreciate it amko_sa, thanks.
    23. August 2011., 05:14:54
  • amko_sa: Just a little more patience.
    22. August 2011., 23:41:28
  • amko_sa: Sorry guys, usually I get these links very quickly, now a little late. As soon as I get links, I will send you a PM  :(
    22. August 2011., 23:38:45
  • normandg: I need the link too!
    22. August 2011., 23:35:39
  • angel1610: would be good to have the link, thanks
    22. August 2011., 18:12:44
  • ebe: send me hirent boot cd 14.1
    22. August 2011., 16:37:17

Enter your email address to receive daily email with 'Newsapp.info Portal' newest content:

Enter your email address:

Delivered by FeedBurner


Page created in 0.338 seconds with 44 queries.