Security Forums

Log in

FAQ | Search | Usergroups | Profile | Register | RSS | Posting Guidelines | Recent Posts

New code could unleash biggest ever Windows worm

Users browsing this topic:0 Security Fans, 0 Stealth Security Fans
Registered Security Fans: None
Goto page 1, 2, 3  Next
Post new topic   Reply to topic   Printer-friendly version    Security Forums Index -> Exploits // System Weaknesses

Special offer!

TechGenix and SolarWinds have partnered to provide a fully-functional, free 21-day trial version of SolarWinds ipMonitor, the WindowsNetworking.com Readers' Choice Award Winner for monitoring applications, servers, and network devices to all visitors who join Security Forums. Sign up to Security Forums and get your copy today! Existing members can pick up a copy from the Members Area.

View previous topic :: View next topic  
Author Message
ShaolinTiger
Forum Fanatic
Forum Fanatic


Joined: 18 Apr 2002
Posts: 2762
Location: Kuala Lumpur, Malaysia

Offline

PostPosted: Sun Jul 27, 2003 3:29 am    Post subject: New code could unleash biggest ever Windows worm Reply with quote

This is somewhat worrying. Could be worse than slammer in the right/wrong hands Rolling Eyes

Quote:
A hacker group released code designed to exploit a widespread Windows flaw, paving the way for a major worm attack as soon as this weekend, security researchers warned.

The warning came Friday, after hackers from the Chinese X Focus security group forwarded source code to several public security lists. The code is for a program designed to allow an intruder to enter Windows computers.

The X Focus program takes advantage of a hole in the Microsoft operating system that lets attackers break in remotely. The flaw has been characterized by some security experts as the most widespread ever found in Windows.


This tickled me though:

Quote:
HD Moore, a security researcher and the founder of the Metasploit Project, has done just that. A well-known hacker and programmer of security code, Moore has taken the Chinese code and improved it. Now the code works for at least seven versions of the operating system, including Windows 2000 Service Pack 0 to Service Pack 4 and Windows XP Service Pack 0 and Service Pack 1.

"I don't like broken exploits, so I fixed it," he said.


From: http://news.com.com/2100-1002_3-5055759.html
_________________
Share your knowledge, it's a
way to achieve Immortality.

Quit Smoking - Darknet Hacking

Kung-Fu Geekery


Last edited by ShaolinTiger on Sun Jul 27, 2003 6:00 pm; edited 1 time in total
Back to top
View user's profile Send private message Visit poster's website
alt.don
SF Boss
SF Boss


Joined: 04 Mar 2003
Posts: 2486


Offline

PostPosted: Sun Jul 27, 2003 5:04 pm    Post subject: Reply with quote

Took me awhile to answer to this as I was wiping off the coffee which came through my nose onto my monitor. Laughing That is priceless though, he "fixed" the sploit. Talk about hoisting their collective petard. Well hopefully MS security is now working on a fix "toute suite". This will be intersting to see if it does hit the wild.
Back to top
View user's profile Send private message Visit poster's website
RoboGeek
SF Mod
SF Mod


Joined: 13 Jun 2003
Posts: 2179
Location: LeRoy, IL

Offline

PostPosted: Sun Jul 27, 2003 5:49 pm    Post subject: Reply with quote

Microsoft Exploit - Service Pack 1.. gotta love it.. Shocked
_________________
Beauty is in the eye of the beer holder.
Back to top
View user's profile Send private message Visit poster's website
CHeeKY
Frequent Member
Frequent Member


Joined: 13 Feb 2003
Posts: 231


Offline

PostPosted: Sun Jul 27, 2003 6:52 pm    Post subject: Reply with quote

got code and exploit, works ok by looks of things..
_________________
"i can stand brute force, but brute reason is quite unbearable. there is something unfair about its use. it is hitting below the intellect."
Back to top
View user's profile Send private message
Aleius
Just Arrived
Just Arrived


Joined: 26 Jul 2003
Posts: 3


Offline

PostPosted: Thu Jul 31, 2003 3:00 pm    Post subject: Reply with quote

is there any program or something scrambler that could protect you from this thing if there is a threat?
_________________
Aleius will find you
Back to top
View user's profile Send private message
r3L4x
New Member
New Member


Joined: 06 Apr 2003
Posts: 41


Offline

PostPosted: Thu Jul 31, 2003 10:32 pm    Post subject: Reply with quote

lol i serously doubt this will be another slammer...an exploit this big, working on so many computers and OS's will be much bigger then slammer, and arrive much sooner.
Back to top
View user's profile Send private message
EricTheBald
Forum Addict
Forum Addict


Joined: 06 Feb 2003
Posts: 307


Offline

PostPosted: Thu Jul 31, 2003 11:14 pm    Post subject: Reply with quote

So what you're saying is that we should be so lucky that it's ONLY as bad as Slammer?


You know, and I have to say that this is purely a hunch on my part, with nothing to base it on more concrete than a gut feeling...
I think we're only days away from getting hit with this.

Well, I shouldn't say "we".

I'm PATCHED dangnabbit! Mr. Green

I may not be a \337 haX0r, but I know where the "Update" button is!
_________________
The older I get the better I feel about tearing up parking tickets and cheating on my taxes.
Back to top
View user's profile Send private message AIM Address
Sgt_B
Trusted SF Member
Trusted SF Member


Joined: 28 Oct 2002
Posts: 1145
Location: Chicago,IL US

Offline

PostPosted: Fri Aug 01, 2003 4:42 pm    Post subject: Reply with quote

August 1st and still no major "attack traffic". Just want to mention I tried running the sploit on windows and nix, and it worked flawlessly. Like _MHz says, its way too easy to run. I rooted my buddies machine for testing (my machine was already patched), and within seconds I was staring at a nice little command prompt.
So are we taking bets on when the worm is coming out? I could see some little monkey scripting this to do all sorts of horrible stuff.
Worse than slammer? You better believe it!
_________________
"All that is necessary for the triumph of evil is that good men do nothing." --Edmund Burke (1729 - 1797)
Back to top
View user's profile Send private message
ZATRiX
Frequent Member
Frequent Member


Joined: 22 Jul 2003
Posts: 106
Location: Canada

Offline

PostPosted: Fri Aug 01, 2003 9:59 pm    Post subject: Reply with quote

This is truly a major threat. I have tried this exploit on my entire work network PCs (15) and every single one of them fell vulnerable to the attack. I am able to get ‘root’ and do well pretty much anything except deleting files. But I’ve found a way to upload files so it’s deadly.

However I have found a simple fix to this “huge” problem. It’s a simple change in your registry without downloading anything major.

HKEY_LOCAL_MACHINE\Software\Microsoft\OLE

Simply set the value to “N” and your set. Of course that isn’t enough, you should never have NetBios enabled etc.
_________________
http://www.zatrixsolutions.com
Back to top
View user's profile Send private message Visit poster's website
scapermoya
Regular Member
Regular Member


Joined: 23 Jul 2003
Posts: 72
Location: Los Angeles

Offline

PostPosted: Fri Aug 01, 2003 10:23 pm    Post subject: Reply with quote

I found it
dcom.c
is that it?
I downloaded a compiler for C, ran it, and it couldnt find any o fthe includes? what do i do?
chinchill.^.
_________________
If toast always lands butter-side down, and cats always land on their feet, what happens if you strap toast on the back of a cat --and drop it?
Back to top
View user's profile Send private message Visit poster's website AIM Address
scapermoya
Regular Member
Regular Member


Joined: 23 Jul 2003
Posts: 72
Location: Los Angeles

Offline

PostPosted: Sat Aug 02, 2003 1:21 am    Post subject: Reply with quote

stupid me,
this only compiles in Linux,
mkay.
_________________
If toast always lands butter-side down, and cats always land on their feet, what happens if you strap toast on the back of a cat --and drop it?
Back to top
View user's profile Send private message Visit poster's website AIM Address
PhiBer
Trusted SF Member
Trusted SF Member


Joined: 11 Mar 2003
Posts: 1092
Location: Your MBR

Offline

PostPosted: Sat Aug 02, 2003 2:27 am    Post subject: Reply with quote

This sux,
Yet another patch i have to run on my server....
Hey where did u guys get the Exploit? I wanna try running it on my system.....u have to compile it in C on a nix box, right?
_________________
"The ultimate measure of a man is not where he stands in moments of comfort, but where he stands at times of challenge and controversy" –Martin Luther King
Back to top
View user's profile Send private message
squidly
Trusted SF Member
Trusted SF Member


Joined: 07 Oct 2002
Posts: 712
Location: Umm.. I dont know.. somewhere

Offline

PostPosted: Sat Aug 02, 2003 2:36 am    Post subject: Reply with quote

Check out Full-Disclosure. And google Smile
I tried it against my box and well what do you know.. my box is up to day and patched Smile
_________________
How to ask questions!
Google is your friend!
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
vlad902
Frequent Member
Frequent Member


Joined: 04 Jan 2003
Posts: 162


Offline

PostPosted: Sat Aug 02, 2003 6:21 am    Post subject: Reply with quote

Meh, no worry to me, my firewall/router doesn't router any packets to the windows boxes and it only routes 22/80 and that's to a *N?X box... Althought I'll set it up so that 137/139 redirect to CharGen Twisted Evil
Back to top
View user's profile Send private message
r3L4x
New Member
New Member


Joined: 06 Apr 2003
Posts: 41


Offline

PostPosted: Sun Aug 03, 2003 2:28 am    Post subject: Reply with quote

one by hdm can either be ran on win32 or a nix system or win32 with cygwin installed.
Back to top
View user's profile Send private message
PhiBer
Trusted SF Member
Trusted SF Member


Joined: 11 Mar 2003
Posts: 1092
Location: Your MBR

Offline

PostPosted: Sun Aug 03, 2003 2:56 am    Post subject: Reply with quote

I finally patched my system!!!!!!!!!! Got it secure again Very Happy

One thing i dont understand, on this webpage....the snort rules, is that the exploit itself?

http://isc.sans.org/diary.html?date=2003-08-01
_________________
"The ultimate measure of a man is not where he stands in moments of comfort, but where he stands at times of challenge and controversy" –Martin Luther King
Back to top
View user's profile Send private message
Display posts from previous:   

Post new topic   Reply to topic   Printer-friendly version    Security Forums Index -> Exploits // System Weaknesses All times are GMT + 2 Hours
Goto page 1, 2, 3  Next
Page 1 of 3


 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Community Area

Log in | Register