WMF Exploit Sold Underground for $4,000
tero1176 writes "Eweek has a story with information from Kaspersky showing that exploit code used in the WMF malware attack was being peddled on underground sites by rival Russian hacker groups for $4,000 in early December. The first sign of an exploit was traced back to the December 1, 2005, a full month before anti-virus vendors started noticing mysterious WMF files rigged with malicious executable code. It serves as more proof that the market for malware is well and truly alive."
how many times will 'jokes' like this be modded funny?
You left out something important: Outlook express would execute code by default, so email was kind of the de facto vector for virus propagation until they started closing down OE [somewhat] and that's when worms really took off.
Before that, it was mostly viruses attached to programs. You'd attach a new virus to some really desirable warez and upload the stuff to a BBS. The BBS owner would run the software and the virus would attach itself to lots of other software, any time they repacked it for their chosen archive format...
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
If you buy an exploit for $4000, chances are you already have a target.
And, you've probably bought one before and made more than the $4000 you are about to spend.
Perhaps they got the trade secrets / passwords they were after in a few hours, not the month it took to become Zero Day, lol, now there's a misnomer !
There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
How appropriate that a Microsoft "Get the Facts" ad should show up at the top of this particular page -- gotta love that Murphy guy when he works in your favor.
To the Microsoft Marketing folks: I'd trade you a fact for a clue but since you have neither facts nor clues I guess we won't be doing business any time soon.
Cheers.
Everything in the Universe sucks: It's the law!
I've seen powerouts but geez. Stone age? People in the Bronze age didnt require MS Windows did they?
At best millions of people will be bugged and Linux and Apple vendors will have a hell of a time selling their OSes.
"Give orange me give eat orange me eat orange give me eat orange give me you." -Nim Chimpsky