New Windows Security AlarmBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/21 7:05:59
2009/11/21 5:42:17
2009/11/21 5:42:17
2009/11/21 5:42:17
Our Partners
Downloads
Windows Security : New Windows Security Alarm
Posted by Max on 2006/11/17 16:49:38 (1671 reads)
Windows Security

Malicious code that exploits a "critical" Windows 2000 vulnerability has been released on the Internet, rising the probability of attacks, experts advised on Thursday.

The code makes use of a security vulnerability in a key operating system module that routes file system and print requests called the "Workstation Service." On Windows 2000 systems, the defect could be exploited via the Net by an unidentified aggressor without any user interaction, increasing the likelihood of the arrival of a Zotob-like worm.


"Somebody could write a piece of code that targets Windows 2000, and that replicates itself, and then you would have a worm go around the Internet," said Monty IJzerman, senior manager in McAfee's Global Threat Group.

The public release of the exploit code comes only two days after Microsoft provided a fix for the flaw. That means that many exposed systems might still be unpatched. While Windows 2000 is an older operating system, it is still largely used, primarily in big business, said vulnerability management company Qualys.


"We scan about 10 million hosts every month, and at least 25 percent of those still run Windows 2000," said Amol Sarwate, a research manager at Qualys. Usually, it takes IT departments between five and eight days to apply a critical patch because of compatibility testing, he said.

Worm risk
Both McAfee and Qualys say a Zotob-like worm attack is possible. In August last year, Zotob slithered into Windows 2000 systems throughout a hole in the plug-and-play feature in the operating system. Zotob surfaced only days after Microsoft offered a fix for the "critical" bug as part of its monthly patching cycle.

Microsoft is aware of the "detailed exploit code" for the Workstation Service vulnerability, which was fixed by security bulletin MS06-070, a company spokesperson said. The software manufacturer is studying the code and plans to publish a security advisory to inform customers, the representative said.

The Workstation Service is a key part of Windows that can't be turned off or easily protected by a firewall, Sarwate noted. "Really, the only solution is to apply the patch as soon as possible," he said. Microsoft does offer some workarounds for the flaw in its security bulletin.

Also on Thursday, security vendor Immunity said it has created exploit code for two other Windows flaws. However, these blueprints are private, meaning they are supplied to users of its penetration-testing tool and are not publicly available.

The two flaws are covered by Microsoft alert MS06-066, which deals with issues that could put Windows 2000 and Windows XP systems at risk from worms. The bugs affect Microsoft's Client Service for NetWare and the NetWare Driver, which let Windows systems access network services on servers running Novell NetWare.

Microsoft also provided fixes for these vulnerabilities on Tuesday, its monthly patch release day. It rated the issues as "important"--one step below its most severe "critical" rating--because the vulnerable components are not installed by default.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.

Poster Thread
katelin3
Posted: 2009/1/28 16:36  Updated: 2009/1/28 16:36
Just popping in
Joined: 2009/1/28
From:
Posts: 2
 Re: New Windows Security Alarm
Hi. Check our site with quality informations: online game, best videos