Computer virus
Rapid creation of exploit code has worried many in the industry
R E L A T E D   C O N T E N T
ADVERTISEMENT

Security experts warn of Windows worm

Exploit code already written for Microsoft patches

Iain Thomson, vnunet.com 14 Oct 2005
ADVERTISEMENT

Fears are growing of a new Windows worm after security companies reported that exploit code is already circulating for three Microsoft patches released on Tuesday.

Within 24 hours of the patches coming out Symantec's DeepSight Threat Management System issued an alert over patch MS05-051. The security firm has issued a signature for its intrusion detection systems.

"The DeepSight Threat Analyst Team has created the signature to detect attempts to bind to the MSDTC RPC interface," said Symantec in a statement. "It has been successfully tested against a client communicating with the interface. "

At the same time, security testing firm Immunity announced that it had developed exploit code for three Microsoft patches. 

The code has only been shared with trusted partners and is intended as proof-of-concept only. Nevertheless its quick creation has worried many in the industry.

"It is always hard to predict these things, especially with worm outbreaks," said Graham Cluley, senior technology correspondent at Sophos.

"But one group has done this, and others will too. It is not too hard to reverse-engineer a patch by looking at what Microsoft has done, and there were some serious patches in this last batch."

Microsoft is advising IT administrators to patch as soon as possible. The advisories and patches are available here:

See also:

MicrosoftUndisclosed security vulnerability to remain unpatched  12 Sep 2005
Optimists v pessimists  18 Aug 2005
Some firms forced to undust their old typewriters  17 Aug 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities