Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

URGENT: ASN.1 BUFFER OVERFLOW HAS BEEN EXPLOITED. PATCH NOW!!! [Code attacks Windows vulnerability]
CNET News.com ^ | 2004-02-17 | Munir Kotadia

Posted on 02/17/2004 2:17:01 PM PST by mosel-saar-ruwer

A piece of code that exploits a critical vulnerability that Microsoft issued a patch for only last week has been posted online, raising fears of an imminent MSBlast-style attack.

On Feb. 10, Microsoft released a patch that fixes a networking flaw that affects all Windows XP, NT, 2000 and Server 2003 systems. The company warned people to patch their systems, because the vulnerability could be exploited by virus and worm writers.

Four days after the patch was released, a piece of code was published on a French Web site that would let anyone exploit the vulnerability, meaning that unpatched customers could be hit with a worm similar to last summer's MSBlast, also known as Blaster.

Richard Starnes, director of incident response at telecommunications giant Cable & Wireless, told ZDNet UK that the code appears to work.

"We ran (the compiled code) against an unpatched XP and Windows 2000 SP3 system, and it took both systems down. It does a buffer overflow and immediately sends the PC into a reboot phase that you can't get out of," he said.

According to Starnes, the published attack could easily be turned into another MSBlast or Code Red type of "blended attack," in which the worm has two distinct modules: one for spreading and the other containing a payload.

"We have started seeing two-phase or two-tier worms--worms that have two attack vectors--one is a propagation vector and one is for launching an attack. The vast majority of worms we have seen only have a propagation payload. But with this one, you can have a propagation payload, and you can have a proper payload--being a DDoS (distributed denial-of-service) platform."

Jay Heiser, chief analyst at IT risk management company TruSecure, told ZDNet that the code on its own is simply a DDoS attack and can cause limited damage, but because it exploits a buffer overflow, it could be used to cause havoc.

"A denial-of-service attack is the equivalent to letting the air out of a tire in a car. It is annoying to the driver and might be fun once or twice for the attacker, but it is not the same thing as allowing you to go for a joyride. The fact that the DoS attack works against the buffer overflow suggests a greater likelihood that a more sophisticated attack is possible," Heiser said.


TOPICS: News/Current Events
KEYWORDS: getamac; headforthehills; lowqualitycrap; microsoft; patchno321345643; theskyisfalling; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 141-150 next last
PATCH NOW

Previous FreeRepublic thread [predicting this] here.

1 posted on 02/17/2004 2:17:04 PM PST by mosel-saar-ruwer
[ Post Reply | Private Reply | View Replies]

To: mosel-saar-ruwer
I downloaded it but it won't run on my computer. Help?
2 posted on 02/17/2004 2:18:32 PM PST by Glenn (What were you thinking, Al?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
Hey, what's this button do...?

OH MY GOD!

(static)

3 posted on 02/17/2004 2:21:13 PM PST by Lunatic Fringe
[ Post Reply | Private Reply | To 1 | View Replies]

To: Glenn
The best patch around is Linux.
4 posted on 02/17/2004 2:21:15 PM PST by taxed2death (A few billion here, a few trillion there...we're all friends right?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: taxed2death
Nevermind. I figured it out. This patch is for a Pee Cee!

I keep forgetting I can't run Pee Cee programs on my Mac.

5 posted on 02/17/2004 2:22:12 PM PST by Glenn (What were you thinking, Al?)
[ Post Reply | Private Reply | To 4 | View Replies]

To: mosel-saar-ruwer
I'VE DONE IT!
6 posted on 02/17/2004 2:22:54 PM PST by Petronski (John Kerry looks like . . . like . . . weakness.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
Maybe I should search all my old 5 1/4" floppies and reinstall a copy of DOS 3.1 and never worry again.
7 posted on 02/17/2004 2:28:09 PM PST by Blue Screen of Death (,/i)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
I predict 91.47% of the post to this thread will be Windows bashing by Mac/Linux users. The other 8.53% of posts will have to wade through all that garbage to get some real info.
8 posted on 02/17/2004 2:28:50 PM PST by Flyer (Don't abandon our military - Re-elect President Bush!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Flyer
LOL.

And I predict that 87.435% of all statistics used in this thread will be made up on the spot.


ROFL!
9 posted on 02/17/2004 2:31:10 PM PST by Johnny Gage (God Bless our Firefighters, our Police, our EMS responders, and most of all, our Veterans)
[ Post Reply | Private Reply | To 8 | View Replies]

To: mosel-saar-ruwer
Thanks for the patch. Your a life saver. (do not attempt to lick, chew, or swallow.) Have a nice day.
10 posted on 02/17/2004 2:31:24 PM PST by Warlord David
[ Post Reply | Private Reply | To 1 | View Replies]

To: Flyer
Mac's rule! Just thought I'd kick it off!
11 posted on 02/17/2004 2:32:11 PM PST by Arkie2
[ Post Reply | Private Reply | To 8 | View Replies]

To: Admin Moderator
PLEASE keep this in Breaking News.

If people don't patch for this thing, the results could be catastrophic.

12 posted on 02/17/2004 2:36:35 PM PST by mosel-saar-ruwer
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
So the SysAdmins on this forum know - there are two unconfirmed reports of this patch (MS04-007) making W2K domain controllers run slowly and refuse to let NT4 assets log in. Patch and test, is my advice. We haven't actually seen that...yet...
13 posted on 02/17/2004 2:38:36 PM PST by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies]

To: Flyer
Yeah, pretty much. "The best patch around is Linux." Yeah, well the best way around all this bullsh*t is to go back to pen and paper, because EVERY OS SUCKS

And I say that as an IT professional that has used just about every stupid iPaq, iPod, iGeorgeForeman, Linsux (no typo there), Winblow$, CrapOS X piece of sh*t out there. And you know what? THEY ALL SUCK!!!!

And please don't point out the irony of my using a computer in order to decry them ;-)
14 posted on 02/17/2004 2:39:54 PM PST by Jinjelsnaps ("Time flies like an arrow, fruit flies like a banana" - Groucho Marx)
[ Post Reply | Private Reply | To 8 | View Replies]

To: mosel-saar-ruwer; Admin Moderator
If we post every POTENTIAL windows problem as Breaking News it will be very 5th headline. This is no more of an emergency than last weeks patch, or the week before’s patch, or…
15 posted on 02/17/2004 2:40:33 PM PST by elfman2
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
here's the perp


16 posted on 02/17/2004 2:41:07 PM PST by MD_Willington_1976
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lead Moderator; Admin Moderator; John Robinson
Is this for real?
17 posted on 02/17/2004 2:41:19 PM PST by Momaw Nadon (Goals for 2004: Re-elect President Bush, over 60 Republicans in the Senate, and a Republican House.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
How do I know you aren't trying to screw up my computer?
18 posted on 02/17/2004 2:41:29 PM PST by nuconvert ("Progress was all right. Only it went on too long.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
Just to be fair


19 posted on 02/17/2004 2:42:34 PM PST by MD_Willington_1976
[ Post Reply | Private Reply | To 1 | View Replies]

To: mosel-saar-ruwer
" PLEASE keep this in Breaking News. If people don't patch for this thing, the results could be catastrophic. "

The same can be said for every MS patch. There is no worm that exploits this hole yet.

20 posted on 02/17/2004 2:43:40 PM PST by elfman2
[ Post Reply | Private Reply | To 12 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 141-150 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson