[Duncan's Home] Duncan's Jotter
faq -  feedback -  home 
Members
Logon   -   Sign Up

RE: #!/usr/bin/geek: Windows DCOM/RPC Remote Exploitation

Msg#3894 - RE: #!/usr/bin/geek: Windows DCOM/RPC Remote Exploitation

In response to: 3893 | <<Back | Next>> | Top of Thread | View Full Thread | Reply | Edit

Posted: 8/13/2003 by Alan McMorran
Modified: 8/13/2003 by Alan McMorran

> I don't know who is worse - Microsoft for allowing this sort of hole in the first place, or the crackers that exploit it!

Or the people that don't keep their machines up to date with critical security patches? All operating systems get them, there's been various patches and updates for Linux for different vulnerabilities before the Linux brigade give it "it only happens to Windows". In this case, there'd been a patch out for almost a month for this problem.

Our office PCs were overrun with it, even though the IT folk had emailed us all last week telling everyone to run windows update.

Thing is, it's probably a blessing in disguise, the virus wasn't malicious, it just reproduced then spread. It could've done a lot worse, scrambled hard disk etc. Now this particular hole is sealed, so when the more virulent malicious incarnation comes out (which it will) most folk will already be patched.

Alan

Enclosures:
None.

Replies:
RE: #!/usr/bin/geek: Windows DCOM/RPC Remote Exploitation ( 8/14/2003 by Damien ODonnell, Label: None. )
>> I don't know who is worse - Microsoft for allowing this sort of hole
RE: #!/usr/bin/geek: Windows DCOM/RPC Remote Exploitation ( 8/14/2003 by Duncan, Label: None. )
Wired News: Worm a Sign of Horrors to Come? ...Microsoft spokesman Sean

Tell ICANN to keep their hands off .org!


Run the HTML validator for this page
Webmaster: web at smeed.org