MS08-067 Exploited for Confidential Data TheftBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/21 7:05:59
2009/11/21 5:42:17
2009/11/21 5:42:17
2009/11/21 5:42:17
Our Partners
Downloads
Windows Security : MS08-067 Exploited for Confidential Data Theft
Posted by Max on 2008/10/28 16:34:40 (765 reads)
Windows Security

PandaLabs, Panda Security's malware analysis and detection laboratory, has detected several malicious files that are exploiting the latest vulnerability announced by Microsoft (MS08-067) to infect users and steal confidential data, including instant messaging passwords, and online login credentials.

The vulnerability affects Microsoft Windows 2000, Windows XP and Windows Server 2003. Individuals can check their systems here: http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

The risk involved in this type of vulnerability is considerable. Users are strongly advised to update their systems as soon as possible, as cyber-criminals have already begun to exploit this security flaw. As long as computers remain unpatched, they will be vulnerable to any of these new malicious codes.

"In addition to email and infected downloads, these vulnerability-exploiting malicious codes are being distributed directly across the Internet, even from legitimate Web pages, so users won't even realize they have been infected," explains Luis Corrons, technical director of PandaLabs.

One particular strain of malware, which exploits this security hole, the Gimmiv.A Trojan, enables its creators to take complete control of the compromised system.

Once a computer has been infected, the Trojan starts gathering the following information:
  • User names and passwords entered in Web pages
  • MSN Messenger passwords
  • Outlook Express passwords
  • System user name
  • Computer name
  • Patches installed
  • Information about the browser
All stolen information is encrypted using the Advanced Encryption Standard (AES) and sent to a remote server.

"As the Trojan allows systems to be controlled remotely, they can then be used maliciously, say, for sending spam or storing stolen data," explains Corrons. "Instant messaging is widely used in both corporate and domestic environments nowadays and this Trojan gives cyber-crooks complete access to information sent across this channel."

PandaLabs advises users to update their operating systems as soon as possible and carry out a full scan of their computers. This can be done for free here: http://www.pandasecurity.com/activescan

About PandaLabs
Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions. More information is available in the PandaLabs blog: http://www.pandalabs.com

About Panda Security

Panda Security is one of the world's leading IT security providers, with millions of clients around the globe and products available in over twenty languages. Our mission is to keep our customers' information and IT assets safe from security threats, giving them the most effective protection with the minimum resource consumption.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.

Poster Thread
edward83
Posted: 2009/2/8 14:39  Updated: 2009/2/8 14:39
Just popping in
Joined: 2009/2/8
From:
Posts: 10
 Re: MS08-067 Exploited for Confidential Data Theft
Hola. Visite mi blog con parejas: espanacams, espanacams directo, sexo chicas