Point, Click, Root.
An anonymous reader writes "The Metasploit Project just released version 2.2 of the Metasploit Framework. This release includes a VNC server payload that can be used with almost any of the Windows exploits. The scary thing about this payload is that the VNC server executes as a new thread in the exploited process; without writing any files to the disk drive. Is this the end as we know it for simple remote command shell exploits? A couple
articles have already mentioned this project."
The cool thing about the VNC payload is that it works if the machine is not logged in, or if the screen is locked.
How does something start off as a "portable network game" and end up as a f*cking remote GUI root?
Un-news
For all the whining about how this makes it so easy for script kiddies, consider that it also makes it so easy for admins who are not in tune with the latest script kiddy 'sploits. This allows them to quickly test their networks in click-n-drool fashion. This can be a very useful tool.
Incidentally, note that this isn't a hole in VNC. It's an attack that installs VNC. VNC doesn't have to be present on the target before the attack.
No, it's quite simple.
/encouraging neighbourhood kids to throw rocks at passing cars.
The easier it is for any 13 year old asshat to exploit these vulnerabilities, the more the value of self-titled "security experts" goes up. Then they can jack small businesses for a 5 grand "consulting fee" to recommend they install a firewall.
They're creating a problem in the hopes they'll be paid to solve it, in short.
Kind of like a windshield salesman going around daring
I don't need no instructions to know how to rock!!!!