Slashdot Mirror


Exploits Circulating for Latest Windows Holes

1sockchuck writes "Exploits are already circulating for at least two (and possibly four) of the Windows security holes addressed in Microsoft's updates on Tuesday. Several working exploits have been released for a new vulnerability in Windows Plug and Play technology, which could be used to spread a worm targeting Windows 2000 machines, according to eEye security, which has released a free scanner to help network admins identify vulnerable computers."

34 of 185 comments (clear)

  1. Microsoft Induced? by Deltaspectre · · Score: 5, Funny

    Perhaps this vulnerability was a 'Feature' to get people to migrate away from Windows 2000?

    --
    My UID is prime... is yours?
  2. Only two or four... by __aaclcg7560 · · Score: 4, Funny

    At least, Microsoft is maintaining great quality control.

  3. Is it really New? by ellem · · Score: 4, Funny

    I mean W2K has been around for about... uh, 5 years?

    So isn't this just an old exploit that was just found?

    See? Having 900,000,000,000 lines of code is a good thing.

    --
    This .sig is fake but accurate.
    1. Re:Is it really New? by 99BottlesOfBeerInMyF · · Score: 4, Interesting

      So isn't this just an old exploit that was just found?

      No. This is an old vulnerability that was just published, and had new exploits written and published for it. That is not to say other exploits have not existed for this vulnerability for the last five years.

    2. Re:Is it really New? by dagr8tim · · Score: 2, Funny
      I mean W2K has been around for about... uh, 5 years? So isn't this just an old exploit that was just found?

      This just goes to prove that hackers are getting as lazy. I mean it took them 5 years to find this hidden feature. Or maybe MS programmers have more forsight than we give them credit for.

      --
      "Does your computer have IP on it?"
  4. Registration form privacy information at eEye by mikeophile · · Score: 4, Insightful

    Our website's registration forms require users to provide contact information (names and email addresses) and financial information (account or credit card numbers). Financial information that is collected is used to bill the user for products and services purchased and is only used internally by eEye. Contact information is used to confirm and ship orders, to contact the user when necessary, and to notify users when new products and services are available. Users may choose not to receive future mailings from eEye; see the Choice/Opt-Out section below. eEye Digital Security may occasionally share visitor contact information with official product resellers that adhere to a comparable privacy policy; visitor contact information is NEVER given to other third-party vendors that are not affiliated with eEye.

    Why do they insist on my personal information if they aren't going to use it?

    They have the ability to let me opt out of of mailing, why don't they provide an opt out for my information in the first place?

  5. It is interesting that... by donleyp · · Score: 5, Insightful

    The exploits came out after the announcement and not before. It begs the question, do we need to give M$ credit for pushing the patch before the exploit became common knowledge? Compare this to Cisco who tried to squash recent publicizing of their vulnerability.

    --
    You got any karma man? I really neeed it. Just a little hit! Come on!
    1. Re:It is interesting that... by uqbar · · Score: 2, Insightful

      Cisco had also patched their vulnerability before the publicity. The whole point of the BlackHat presentation was to encourage admins to use the patch, and to shame Cisco for underplaying how serious the issue is.

    2. Re:It is interesting that... by timster · · Score: 2, Insightful

      The problem is that now it means both things, and every time you encounter it you have to reason out which meaning is being used. So it's currently better to not use the expression at all, and substitute "raises the question" for one meaning and "circular logic" for the other.

      Evolution of language isn't a problem, but useless entropy like forgetting the meaning of an expression makes clear and effective writing more difficult. There are those of us who like to read clear and effective writing, so we wish that it were easier to do.

      --
      I have seen the future, and it is inconvenient.
    3. Re:It is interesting that... by Changa_MC · · Score: 2, Funny

      To beg a question is to ask a question to answer itself. (Please, please, question, give me your answer!)

      Like a little kid saying, "Do you like this, say yes?"
      Begging, so that you'll know what you're supposed to say.

      --
      Changa hates change.
    4. Re:It is interesting that... by Sheepdot · · Score: 2, Insightful

      I haven't the faintest clue why your comment is insightful.

      Let me give you some examples of exploits (ie worms) that came out after patches: Blaster, Sasser, Nimda (MS patched this 330 days before the worm actually hit). Code Red is the only one that immediately comes to mind as a worm that hit before the patch, and even in that case, MS didn't know ahead of time that IIS was exploitable. It was 0-day.

      In the case of the Plug & Play exploit, it became common knowledge *because* of the patch, which was reversed engineered to see what it fixed.

      In the case of the other item, Microsoft acknowledged earlier that spyware companies were already exploiting the java proxy dll 0-day and thus created the patch.

      In the first case the patch made the exploit common knowledge, in the second, the common knowledge came before the patch. So the answer to your question is: no.

      Don't get me wrong, MS is getting better about patching, and they should be commended for their efforts in finding the java proxy IE exploit "in the wild" on their own without a security company having to release anything, but they don't need to be commended for releasing their regular monthly patches.

      Patching for security issues is not something that a vendor is rewarded for. They are expected to do it.

  6. I don't know exactly why... by Stanistani · · Score: 2, Funny

    But I'm reminded of a childhood verse...
    "The worms crawl in, the worms crawl out
    The worms play pinochle on your snout..."

    1. Re:I don't know exactly why... by Fishstick · · Score: 2

      Lovely little nursery rhyme, that
      Did you ever think, as a hearse goes by,
      That you might be the next to die?
      They wrap you up in a big white sheet,
      And bury you down about six feet deep

      They put you in a big black box,
      And cover you up with dirt and rocks,
      And all goes well, for about a week,
      And then the coffin begins to leak!

      The worms crawl in, the worms crawl out,
      The worms play pinochle on your snout.
      They eat your eyes, they eat your nose,
      They eat the jelly between your toes.

      A great big worm with rolling eyes,
      Crawls in your stomach and out your eyes,
      Your stomach turns a slimy green,
      And pus pours out like whipping cream.

      You spread it on a slice of bread,
      And that's what worms eat when you're dead.

      Alternate / Additional Lines:

      They wrap you up in a long white shirt
      And cover you up with rocks and dirt

      They put you in a long pine box
      And cover you over with dirt and rocks

      The worms that crawl in are lean and thin
      The worms that crawl out are fat and stout

      Your eyes fall in and your hair falls out
      Your brains come pouring out your snout

      They use your bones as telephones
      and call you up but you're no longer at home

      Your eyes pop out, your teeth decay
      and that's the end of a peaceful day

      You turn the color of sickening green
      And pus comes out like butter and cream
      You wipe it up with a piece of bread
      And that's what you eat when you are dead

      They eat your eyes, they eat your nose
      They eat the jelly between your toes

      Your stomach turns a mossy green
      And pus comes out like fresh whipped cream
      You wipe it up with a piece of bread
      And that's what you eat when you are dead

      --

      There is much cruelty in the universe, John.
      Yeah, we seem to have the tour map.

  7. Free, but not without pain by bitslinger_42 · · Score: 3, Insightful

    Is anyone but me getting sick of these companies releasing "free" tools that require you to register for their incessant spam, phone calls, and other marketing harassment in order to download? Yes, I understand that they spent money to develop the tool, but what if I want to scan my home network? MySQL isn't too bad, at least. They have the marketing signup, should you be interested, but provide a link to download without all the crap.

    [Wanders off muttering about the good old days of gopher and archie]
  8. Why is this surprising? by SkiifGeek · · Score: 3, Interesting

    The recent article on the front page here (2 down at the moment), talks about vulnerabilities linked to MS05-038 being in the wild in mid July (actually quite a bit earlier, but we will give them the benefit of the doubt). There have been a number of minor exploits in existence for at least a month and a half with respect to some image handling capabilities through IE (also MS05-038).

    Security-Protocols claimed to have discovered the vulnerability linked to MS05-041, and there were some minor claims that other people had been able to make it into exploits which weren't widespread.

    I initially thought that the Plug and Play vulnerability was linked to a report on an overflow with respect to handling USB devices (which has also been reported), but it seems to be much worse.

    I am fully aware of the reasons why companies EOL their software, but Microsoft's cessation of mainstream support for Win 2000 might be coming back to bite them, given that Win 2000 is just as vulnerable to these exploits as Win XP and 2003, if not more so.

  9. Unless I'm mis-reading this... by goldspider · · Score: 4, Insightful

    ...Microsoft patched the holes BEFORE the exploits started circulating?

    If that's the case, what's the problem?

    --
    "Ask not what your country can do for you." --John F. Kennedy
    1. Re:Unless I'm mis-reading this... by Espectr0 · · Score: 4, Insightful

      Simple. It is known that exploits are made after MS releases the patch, by reverse engineering them. Since 90% of the people is stupid and don't patch their systems (i made this up) then these people get hit.

      My rant is not against MS. It's against people (supposedly people with knowledge) don't take the time to update their systems. SP2 actually improved this by trying to push the updates in the user's throats.

  10. Re:Not to worry... by guildsolutions · · Score: 3, Interesting

    Microsoft with all its massive billions of dollars, charging in excess of $300 for a full, licesned version of Windows XP Proffessional... Cannot afford to write clean, bug free code?

    As a programer myself I am often faced with the idea of completely re-writing my code, not just leaving the function sit, while being unused.

    Compare to Apple's OS X (granted, the numbers argument about there is not a mass majority to spread a major virus even if it was to be discovered), why cant Microsoft decide to take shape, and start producing a REAL operating system that is built upon firm solid foundations of bug free (realitivly) code. They have admited in the past that they have pushed features ahead of security, and yet our major corporations still tout that microsoft is secure enough for there senstive finiancial information.

    Give me a break will ya? I really just wish that microsoft would have a much more open beta, much more strict adherance to quality code, and less mouthpeices saying how great there stuff is.

  11. Scanner? by Fear+the+Clam · · Score: 5, Funny

    "...eEye security, which has released a free scanner to help network admins identify vulnerable computers.

    What, the Windows startup screen wasn't sufficient to identify vulnerable computers?

  12. In other news... by Anonymous Coward · · Score: 2, Insightful

    Hundreds of vulnerabilities discovered in Linux since the release of a distro:

    http://www.mandriva.com/security/advisories?dis=10 .1

    But of course, that's not newsworthy because it doesn't involve hating Microsoft. This ain't a troll; it's an attempt to show that BOTH systems have pretty lame security track records, yet all we hear about is Windows.

    Look at that list above. Given 300 million clueless users running that Mandrake instead of Windows, don't you think there'd be exploits for that plenthora of holes too?

    1. Re:In other news... by BabyDave · · Score: 2, Insightful
      Hundreds of vulnerabilities discovered in Linux since the release of a distro: http://www.mandriva.com/security/advisories?dis=10 .1
      Of course, Windows doesn't come with the hundreds (thousands?) of applications that Mandriva does, and so it's a bit unfair to compare the Mandriva security advisory list (which includes fixes for MySQL, Apache, Perl, Mozilla, Vi, etc etc) to the Windows list.
  13. Re:Well give and take credit from Microsoft by toddbu · · Score: 2, Insightful
    It's exactly this kind of argument that people need to make to their bosses when talking about using open source software. Your company should decide when the life of a piece of software is over, and they can make this decision on factors like "Do I want to patch this or install a new version?" And because some vulernable software like IIS is built right in, you can't just upgrade that one piece if the vendor decides they'll no longer fix it for your platform.

    Microsoft's biggest problem really is all this integration that they do when it doesn't need to be done. Yes, it's nice that I can click on a link in an email and open a document in my browser. That's a good use of integration. But when much of the system depends on a couple of dlls that can't be upgraded without changing the whole system then that's not good at all. I think that there's a huge appeal to the F/OSS model and decoupling of software when it comes to this kind of thing.

    --
    If you don't want crime to pay, let the government run it.
  14. link by Anonymous Coward · · Score: 2, Informative

    right here

    -WH

  15. Re:Just Upgrade by Skruffy42 · · Score: 3, Insightful

    I still have people using 75Mhz machines with windows 95, and most of my users are running 2000. We don't need to or have the budget to upgrade everyone to a new box with XP on it just so they can use word/excel, and email each other porn.

  16. nessus plugins available by sgt+scrub · · Score: 3, Informative

    If you need to test the machines on your network Nessus http://nessus.org/ has released plugins.

    --
    Having to work for a living is the root of all evil.
  17. Re:Not to worry... by whoever57 · · Score: 3, Interesting

    I think that you have to assume there will be bugs in the code. I am sure Apple has bugs. The real question, is: why are there so many listening ports on a Windows NT/2K/XP machine? Even one that has no files shared for users. What does it need them for? MS recommends running a firewall, which rather defeats the purpose of any listening ports, including such things as the administrative shares. In this case, we have some code that is supposed to detect new hardware apparently listening on the Ethernet port. Why? New hardware is going to fly down the network? Wow! MS should patent that now since it would put UPS and Fedex out of business. So, I don't think it is so much a bug as "what in $DEITY's name were they thinking when they designed this feature?"

    --
    The real "Libtards" are the Libertarians!
  18. Exploiting the Exploit by Anonymous Coward · · Score: 2, Interesting

    The company distributing this requires you provide personal information just to pick up a small scanner which is entirely unnecessary. The purpose it seems behind distributing these little tools is to collect this information for sale and for use in sales.

    I would recommend that users stop using slashdot.org as a way to distribute pointless software in an attempt to collect free user data.

  19. steps ahead by fihzy · · Score: 4, Funny


    Once again: (original at http://slashdot.org/comments.pl?sid=71367&cid=6457 101)

    10) find big remote vulnerability in product
    20) perfect the exploit
    30) have fun with it for months
    40) find another big hole in same product
    50) perfect exploit for hole
    60) alert vendor about original hole
    70) have fun with new hole
    80) goto 40

  20. Re:Just Upgrade by Tourney3p0 · · Score: 2, Insightful

    How exactly is Windows 2000 "out of date" by any standard except the date it was released? Windows XP is horrid compared to Windows 2000. Very few people I know have "upgraded" to Windows XP from Windows 2000. It's easier and cheaper to open the case and remove a stick of ram. Install a Yoshi's Island skin, and you have instant 2000->XP upgrade. Mentalities such as yours are why you need a 3 Ghz P4 and 512 MB of RAM just to open Microsoft Word in less than 30 seconds.

  21. Re:And Linux doesen't?!?!? by chez69 · · Score: 2, Informative

    the enterprise versions are supported for 3 years. fedora is just a testbed, most of the folks that use it (including me) realize this.

    if you want long term support, buy something that has it.

    --
    PHP is the solution of choice for relaying mysql errors to web users.
  22. Here's some news for you, chum. by Anti-Trend · · Score: 3, Informative

    First of all, Linux distros support every package on the system, not just the core files like MS update. That means perl, MySQL, apache, even the modules for apache. Everything. With that in mind, compare the Secunia security reports for Mandrake 10.0 and Windows XP Pro 10.0, which hit the market at about the same time. Have a look at the amount of unpatched vulnerabilities in both and see if you can still come to the same conclusions. Sheesh!

    --
    Working in a DevOps shop is like playing in a band made up entirely of keytarists.
  23. Let's Hear Ira Winkler Now by Master+of+Transhuman · · Score: 2, Interesting


    He's been writing that Mike Lynn did the industry a disservice by revealing the buffer overflow class of Cisco vulnerabilities.

    His logic is that as soon as you reveal a vulnerability, you accelerate the exploits, and therefore vulnerabilities should not be revealed. (In other words, the classic "security through obscurity argument.")

    He seems to think it makes more work for him and other security people.

    I pointed out to him that if we follow his logic, no vulnerability and no patch would ever be released. Here we have exploits following a patch. Does he now think Microsoft should not have released the advisory and patch because it "accelerated" the development of an exploit which will affect unpatched systems?

    This is exactly his logic with Mike Lynn's actions. He claims revealing the buffer flaws, even though Cisco has patched the two actual flaws found, will cause an exploit to appear that will affect unpatched systems and cause him "more work."

    I pointed out to him that he should thus blame Microsoft for patching the SQL Server flaws even though most admins didn't patch their servers in time for the worms that took advantage of them.

    I also pointed out to him that if he thinks security is easy and he can't handle the "extra work" exploits cause, get out of the business.

    His real motivation, of course, which I also pointed out to him, was simply sour grapes that he didn't get the press for revealing the flaws. The security business is very competitive, and every time a researcher announces something, everybody else denounces him as wrong, premature, or not following proper "protocol." All this just to keep THEIR names - and by extension, the same vulnerabilities they're complaining about - in the trade press. It's hypocritical.

    --
    Richard Steven Hack - This sig is TOO GODDAMN SHORT TO DO ANYTHING USEFUL WITH! MORONS!
  24. Re:Exploits circulate after bug report by bhudson · · Score: 2, Interesting

    If you are a black hat, and have a working exploit, you generally don't want to blast it all over the net, but use it judiciously to get as much as possible out of it before it is discovered. Once it becomes commonly known, and a patch exists, you know you don't have much time left, so you take advantage of it as much as possible.

    I'm not saying that is the case with this particular exploit, but Microsoft wants everyone to believe that we wouldn't have to worry about exploits if those white hats would just stop finding problems with MS software.