![]() |
|
#1
|
|||
|
|||
|
Quote:
|
|
#2
|
||||
|
||||
|
Considering what massive hit Windows 7 has been so far, I'm surprised it's taken this long to find one! I'll be upgrading to windows 7 soon and I can't wait.
![]()
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#3
|
|||
|
|||
|
From the article:
Quote:
Note also that these ports were the ones that Conficker exploited. A MSDN blog had this at the end of last year: MS08-067 and the SDL http://blogs.msdn.com/sdl/archive/20.../ms08-067.aspx Quote:
It's pretty evident that insuring that people have a firewall/router properly configured would prevent a lot of problems. One caveat is with those who have file sharing enabled, in which case other precautions need to be taken. regards, -rich |
|
#4
|
|||
|
|||
|
From DailyTech:
Quote:
|
|
#5
|
||||
|
||||
|
Quote:
Quote:
See: Protect Your PCs from Windows 7's Zero-Day Exploit November 12, 2009 http://www.pcworld.com/businesscente...y_exploit.html Protect Your PCs from Windows 7's Zero-Day Exploit November 13, 2009 http://www.thestandard.com/news/2009...s+%28all%29%29 Laurent Gaffié, in his blog, wrote that IE can be a trigger for the exploit, and his code shows SMB/Port 445 launching the Denial of Service: Code:
Windows 7 / Server 2008R2 Remote Kernel Crash http://g-laurent.blogspot.com/2009/1...te-kernel.html The IE trigger may launch the exploit internally via Netbios and the ports, but no working example has been given. Microsoft adds to the confusion in its Advisory: Microsoft Security Advisory (977544) http://www.microsoft.com/technet/sec...ry/977544.mspx Quote:
Finally, an observation by Chet Wisniewski, senior security adviser at Sophos: First Windows 7 Exploit Appears To Evade SDL Process By Jennifer LeClaire November 13, 2009 10:23AM http://www.newsfactor.com/news/First...d=031002F6WXWX Quote:
---- rich |
|
#6
|
|||
|
|||
|
Quote:
|
|
#7
|
|||
|
|||
|
Isn't it common that port 135-139 and 445 is blocked by default in routers and software firewalls? At least, it is for me...
__________________
The vault - Hidden File Scanner - ADS Engine and more |
|
#8
|
|||
|
|||
|
Quote:
Here, the misquote is most unfortunate, since the person identified with the quote is the author of the exploit code and the one who notified Microsoft. The correlation with IE specifically to this vulnerability has not been thoroughly discussed nor demonstrated. regards, ---- rich |
|
#9
|
|||
|
|||
|
Quote:
This came up during the MS08-067 RPC (remote procedure call) vulnerability, also involving ports 139, 445, which the Conficker worm later used. In a Windows Secrets Newsletter from October of last year, Susan Bradley noted: Rare out-of-cycle patch emphasizes the risk - MS08-067 http://windowssecrets.com/comp/081024 Quote:
regards, -rich |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|