Poll
Navigation
User login
Symantec Security
Increase in Exploit Attempts Against MS08-067
Microsoft Security bulletin MS08-067 was an out-of-band security update that was released on October 23, 2008, to address a critical remotely exploitable vulnerability that was being exploited in the wild. The Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability that was addressed
Microsoft Patch Tuesday - November 2008
Hello and welcome to this month’s blog on the Microsoft patch releases. This is a light month, with two bulletins covering four vulnerabilities.
Acrobat util.printf() Exploit Detected with Existing IPS Signatures
It appears that last night, an exploit for the Acrobat util.printf() vulnerability was added to a well known Web attack toolkit. The attack exists as a compressed PDF. Once decompressed, the exploit is encoded with a simple eval()+concatenation block:
ActiveX File Overwrite/Delete Vulnerabilities - Continued
In a blog article from last year, I discussed the rise in popularity of exploits using ActiveX overwrite/delete vulnerabilities due to their ease of use. Since that time, we have seen over 100 such vulnerabilities.
MS08-067 Exploited in the Wild
I am sure by now that many have read about Trojan.Gimmiv exploiting the new MSRPC vulnerability. While we have not seen any evidence of Gimmiv replicating by itself, we analyzed a second component, related to Gimmiv, which is able to exploit the vulnerability patched on Wednesday.
Tracking MS08-067
This morning Microsoft released an out-of-band security update - MS08-067 - for a vulnerability in the Server service. This issue is tracked as BugTraq ID 31874. This issue affects all supported versions of the Windows operating system.
Web Attacks Using Microsoft Help and Support Center Viewer
The Symantec DeepSight Threat Analysis team recently observed an interesting attack development related to a known vulnerability type. This seemingly new technique allows attackers to execute a malicious payload immediately on a victim's system, where in the past they weren't able to achieve instant code execution by exploiting such vulnerabilities.
Microsoft Patch Tuesday for October 2008
Hello and welcome to this month’s blog on the Microsoft patch releases. This is another fairly heavy month, with 11 bulletins covering 20 vulnerabilities.
Recent Microsoft Vulnerability Exploited in the Wild
Not surprisingly, attackers are again targeting vulnerabilities from the latest set of Microsoft Security Bulletins. This time around, it is the Microsoft Media Encoder ActiveX overflow patched in MS08-053. This attack chronology is another example of the rapid adoption of public exploits into widely deployed exploit toolkits.
Microsoft Patch Tuesday for September 2008
All of the vulnerabilities this month are client-side issues rated "critical." Five of the issues affect the GDI+ graphics library; the rest affect Media Player, Microsoft Office, and Media Encoder. All of the issues have the potential to see active exploits, but the GDI+ vulnerabilities have the most avenues of attack and affect the most systems. The OneNote protocol handler vulnerability is fairly trivial to exploit.
Cisco WebEx Meeting Manager Drive-By Exploit
On August 20, our honeypots began to receive attacks against the Cisco WebEx Meeting Manager vulnerability. This August 6 vulnerability exists in the ActiveX control used by WebEx to permit users to participate in meetings via Internet Explorer. Users running the vulnerable version of the Webex control who happened upon a Web site distributing the exploit would become infected. The first exploits that we have seen so far have been served via gaming sites that have had the exploit package injected on to them.
Microsoft Patch Tuesday for August 2008
Hello and welcome to this month’s blog on the Microsoft patch releases. This is one of the largest releases with 11 bulletins covering 26 vulnerabilities. Seventeen of the vulnerabilities are client-side issues rated “critical;” the remaining nine are rated “important.”
Site Counter
- Site Counter: 38687Unique Visitor: 4739Registered Users: 214Unregistered Users: 1Published Nodes: 8Unpublished Nodes: 0Your IP: 38.107.179.232Since: 2008-10-05
***Disclaimer***
Any content, media, situations, or beliefs that are shown or expressed on Novation Networks' Web servers are not the content or beliefs of Novation Networks LLC. Therefore, we will not be held liable for any content which is hosted by our customers on our servers.
All Content is Copyrighted 2008 Novation Networks LLC. Any images, content or design taken from this website and found will be prosecuted to the fullest extent of the law.
