About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Society > News of the World
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

News of the World Current events discussion and links to stuff that's happening right now. Who needs CNN when you have totse?

Reply
 
Thread Tools Display Modes
 #1 
Old 2008-11-29, 15:20
KillSwitch_J KillSwitch_J is offline
Regular
 
Default Internet worm exploits Windows vulnerability

November 26, 2008 1:39 PM PST
Posted by Elinor Mills



A worm dubbed Win32/Conficker.A is making the rounds on Windows machines, exploiting a security hole that Microsoft released a patch for in October, Microsoft said on Wednesday.

The number of attacks have increased over the past couple of days, exploiting a critical vulnerability that was addressed by security update MS08-067.

The malware mostly was spreading inside corporations, but also hit several hundred home PCs, Microsoft said in a posting on the Microsoft Malware Protection Center Blog.

"It opens a random port between port 1024 and 10000 and acts like a Web server. It propagates to random computers on the network by exploiting MS08-067. Once the remote computer is exploited, that computer will download a copy of the worm via HTTP using the random port opened by the worm. The worm often uses a .JPG extension when copied over and then it is saved to the local system folder as a random named dll," the posting said.

"It is also interesting to note that the worm patches the vulnerable API in memory so the machine will not be vulnerable anymore. It is not that the malware authors care so much about the computer as they want to make sure that other malware will not take it over too," Microsoft said.

Most of the infections are in U.S. PCs, but there have been reports from Germany, Spain, France, Italy, Taiwan, Japan, Brazil, Turkey, China, Mexico, Canada, Argentina, and Chile. The worm avoids infecting Ukrainian computers, for some reason, Microsoft said.

Several bots, under the generic name Backdoor:Win32/IRCbot.BH, also are exploiting the security hole. They drop a backdoor Trojan that connects to an IRC server to receive commands.


Source:
http://news.cnet.com/8301-1009_3-10109080-83.html

Damn worms! Someone should create a "cyber-piranha" program and then set it free on the web to gobble up all of the worm programs.
 #2 
Old 2008-11-30, 22:12
Regular
 
Default Re: Internet worm exploits Windows vulnerability

"It is also interesting to note that the worm patches the vulnerable API in memory so the machine will not be vulnerable anymore.I found it interesting also.
Closes the door behind it so nothing else comes in.......not often you come across a selfish virus. Roll Eyes (Sarcastic)
 #3 
Old 2008-11-30, 22:23
Regular
 
a.K.a Dfg (PK)
Default Re: Internet worm exploits Windows vulnerability

I just checked my AV update list and i am protected and patched.

Follow basic security procedures and chances of getting pwned by a worm or virus are greatly reduced.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics