The obvious thing is to apply patch MS05-051 on at least your [Windows 2000], ... We do know the port 3372 scanning started in full force, likely in order to acquire target lists. If you can't patch, at least make sure port 3372 is closed. |
The obvious thing is to apply patch MS05-051 on at least your [Windows 2000]. We do know the port 3372 scanning started in full force, likely in order to acquire target lists. If you can't patch, at least make sure port 3372 is closed. |
The problem with this attack is that it is so hard to defend against for the average user. |
The Snort issue is more dangerous because the exploit is really simple. |
The story here is if you are hit, you do have other vulnerabilities than this problem. |
The vulnerability itself has been known about for a while, but it was only a problem for a denial-of-service attack that would sometimes cause IE to crash. Up until now, no one knew how to mark the code and find it in memory to execute a remote code attack. |
These are the sort of problems that we typically see when patches don't cooperate well with various third-party software and some of the less used functions of Windows, |
This laptop will infect your systems from the inside. |
This should allow Windows programs to display WMF files normally while still blocking the exploit. |
Typically, the infective vector is a laptop connected to unsecured networks, |
Users have to kill out of the browser and start over again. This stalled browser creates a DOS (denial of service) condition. |
We carefully checked this patch and are 100 percent sure that it is not malicious. The patch is, of course, not as carefully tested as an official patch. But we feel it is worth the risk. We know it blocks all exploit attempts we are aware of. |
We do suspect that Microsoft will still release an early patch given the imminent danger to its customers from this flaw. As stated by the company about two years ago, patches can be released within two days if needed. Based on prior public commitments, we do suspect that Microsoft will issue the patch early once they are convinced that customers require the use of Internet Explorer in production environments. |
We've basically built doors now for 4,000 years and still have burglaries. |
What hackers are trying to find is, if they can make a bad Excel file or a bad Word file, does the program crash and allow them to compromise the system. |