Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Results 1 to 3 of 3
  1. #1
    Moderator
    Points: 49,131, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 47.0%
    Achievements:
    Recommendation Second ClassRecommendation First Class31 days registered3 months registered100 Experience Points

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,554
    Liked
    546 times

    Bug Remote exploit released for Windows Vista SMB2 worm hole

    "Security researchers at penetration testing firm Immunity have created a reliable remote exploit capable of spawning a worm through an unpatched security hole in Microsoft’s dominant Windows operating system.

    A team of exploit writers led by Kostya Kortchinsky attacked the known SMB v2 vulnerability and created a remote exploit that’s been fitted into Immunity’s Canvas pen-testing platform. The exploit hits all versions of Windows Vista and Windows Server 2008 SP2, according to Immunity’s Dave Aitel.

    Immunity’s Canvas is used by IDS (intrusion detection companies) and larger penetrating testing firms as a risk management tool.

    Exploit writers at the freely available Metasploit Project are also close to finishing a reliable exploit for the vulnerability, according to Metasploit’s HD Moore.

    The vulnerability, which was originally released as a denial-of-service issue, does not affect the RTM version of Windows 7, Microsoft said. It appears Microsoft fixed the flaw in Windows 7 build ~7130, just after RC1.

    Windows Vista and Windows Server 2008 users remain at risk.

    In the absence of patch, Microsoft recommends that users disable SMB v2 and block TCP ports 139 and 445 at the firewall
    ."

    Source

    You might watch a video of the exploit here

    https://www.immunityinc.com/documentation/smbv2.html

  2. #2
    Tech God
    Points: 9,289, Level: 64
    Level completed: 80%, Points required for next Level: 61
    Overall activity: 0.5%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    May 2008
    Location
    Seattle, WA
    Posts
    1,649
    Liked
    0 times
    This exploit does not effect W7, nor XP. If you would like to see a listing of all operating systems effected, go here to see if you are on the list:

    http://www.microsoft.com/technet/sec...ry/975497.mspx

    If you are using an effected OS, that same site offers a work-around that will work until a patch has been fully tested.

  3. #3
    Moderator
    Points: 49,131, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 47.0%
    Achievements:
    Recommendation Second ClassRecommendation First Class31 days registered3 months registered100 Experience Points

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,554
    Liked
    546 times
    Thank you so much for the link you provided Polkadot
    While waiting for an official patch, that link will be very useful for Vista and Windows Server 2008 users
    Last edited by leofelix; 09-22-2009 at 09:19 AM. Reason: correction

 

 

Similar Threads

  1. iPack Exploit Kit Bites Windows Users
    By leofelix in forum Spyware/Viruses
    Replies: 8
    Last Post: 04-22-2010, 05:29 AM
  2. DirectX 11 For Windows Vista Released
    By A Guy in forum General Forum
    Replies: 0
    Last Post: 10-31-2009, 02:50 PM
  3. 3 Million hit by Windows Worm
    By Mark in forum General Forum
    Replies: 11
    Last Post: 01-20-2009, 12:20 PM
  4. Replies: 3
    Last Post: 12-20-2008, 12:55 AM
  5. Replies: 3
    Last Post: 08-29-2007, 09:30 AM

Tags for this Thread

All times are GMT +8. The time now is 01:53 AM.