Computer virus
Rapid creation of exploit code has worried many in the industry
R E L A T E D   C O N T E N T
ADVERTISEMENT

Security experts warn of Windows worm

Exploit code already written for Microsoft patches

Iain Thomson, vnunet.com 14 Oct 2005
ADVERTISEMENT

Fears are growing of a new Windows worm after security companies reported that exploit code is already circulating for three Microsoft patches released on Tuesday.

Within 24 hours of the patches coming out Symantec's DeepSight Threat Management System issued an alert over patch MS05-051. The security firm has issued a signature for its intrusion detection systems.

"The DeepSight Threat Analyst Team has created the signature to detect attempts to bind to the MSDTC RPC interface," said Symantec in a statement. "It has been successfully tested against a client communicating with the interface. "

At the same time, security testing firm Immunity announced that it had developed exploit code for three Microsoft patches. 

The code has only been shared with trusted partners and is intended as proof-of-concept only. Nevertheless its quick creation has worried many in the industry.

"It is always hard to predict these things, especially with worm outbreaks," said Graham Cluley, senior technology correspondent at Sophos.

"But one group has done this, and others will too. It is not too hard to reverse-engineer a patch by looking at what Microsoft has done, and there were some serious patches in this last batch."

Microsoft is advising IT administrators to patch as soon as possible. The advisories and patches are available here:

See also:

MicrosoftUndisclosed security vulnerability to remain unpatched  12 Sep 2005
Optimists v pessimists  18 Aug 2005
Some firms forced to undust their old typewriters  17 Aug 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities