View Full Version : Window Worm Warning... update NOW


click
Aug 11th, 06, 03:55 PM
I just got a tech warning from local computer guru about another malicious worm type virus that could show up very soon. Windows has patches to help stop it but if you dont update your Windows operating system regularly, do it NOW. Patch links are below the article. Lets all be aware and alert.

By Gregg Keizer, TechWeb
5:43 PM EDT Thu. Aug. 10, 2006

As the spotlight on a dangerous Windows vulnerability grows brighter by the hour, security analysts Thursday said that it's not hype driving the alarms, but genuine fear that a major worm attack is just days away.

"This is no drill," said Mike Murray, director of research at vulnerability management vendor nCircle. "And no, this isn't an overreaction. We've always said that some day there would be another big, serious vulnerability.

"Well, this is the one."

The bug in question is one of 23 patched Tuesday by Microsoft, and one of 16 tagged by the Redmond, Wash. software developer as "critical." It affects all currently-supported versions of Windows, can be exploited without end users lifting a finger, and in some experts' eyes, rivals the bug that led to 2003's destructive MSBlast attack.

Recent developments have turned up the heat over the vulnerability spelled out in Microsoft's MS06-040 security bulletin. Wednesday, Department of Homeland Defense (DHS) called out a rare warning, and Microsoft acknowledged that the patch should be at the top of every computer user's or administrator's to-do list.

Wednesday, the DHS, which also operates the United States Computer Emergency Readiness Team (US-CERT), took the unusual step of issuing its own warning. "Windows users are encouraged to avoid delay in applying this security patch," said the DHS release. "This vulnerability could impact government systems, private industry, and critical infrastructure, as well as individual and home users."

Earlier that day, Microsoft said "we are recommending that customers give priority to MS06-040."

Thursday's deepening concern was fueled by several releases of new exploit code. HD Moore, co-creator of the Metasploit Framework, took his exploit for the MS06-040 vulnerability public early in the day. Later, after Symantec's research team confirmed that Moore's code, which targets Windows 2000, XP, and Server 2003, results in a denial-of-service (DoS) attack, repeated its previous warning to "patch as soon as possible."

Other analysts agreed, and more.

"Because it's been added to the Metasploit Framework, a lot of hackers will be look at [Moore's exploit code]," said Ken Dunham, the rapid response team director at security intelligence firm VeriSign iDefense. "With some tweaking, his code could potentially be turned into a worm."

The availability of exploit code, even rudimentary code that doesn't yet let an attacker hijack a PC, along with the scope of the vulnerability, means that it's guaranteed MS06-040 will get lots of attention. But whether it ends up as a worm ala 2003's MSBlast is still uncertain, Dunham said.

"There will be a lot of [attacker] activity around this, but we'll have to watch how this matures in the next few days to know whether a worm's probable." nCircle's Murray was more sure.

"We'll see proof-of-concept code that takes over the system within 48 hours," Murray said.

"It's only a matter of time or luck before this turns into the scale of MSBlast. Essentially, every Windows system is vulnerable. This is one of those worst-case 'pull the plug on the Ethernet cable' events."

Exploits have also been released for commercial customers of Core Security's Core Impact testing tool and Immunity 's Canvas software, Dunham noted.

Early Thursday, Christopher Budd, security program manager at Microsoft's Security Response Center (MSRC), affirmed the company's patch-now stance on MS06-040. "We've got our Emergency Response process teams watching for any possible malicious activity," wrote Budd on the center's blog. More than 100 million copies of the MS06-040 patch were downloaded in the first 30 hours after its Tuesday release, he added.

The next two to four days should tell the tale of the bug.

"It's very important to patch right now," said Dunham, "because most exploits are developed in the first week after the vulnerability is disclosed. It not by then, then four or five days later, but by then most people are patched."

"This is the real thing," said Murray. "It's not a false alarm."

The Windows 2000, XP, and Server 2003 patches for the MS06-040 Server service flaw can be obtained via Microsoft and Windows Update services.

Run windows updates from here (http://www.microsoft.com/downloads/details.aspx?familyid=2996b9b6-03ff-4636-861a-46b3eac7a305&displaylang=en)

They also recommend this batch of 5 other patches (http://www.microsoft.com/downloads/thankyou.aspx?familyId=2996b9b6-03ff-4636-861a-46b3eac7a305&displayLang=en&oRef=)

CFunK
Aug 11th, 06, 06:06 PM
Or use Linux! :D

BNZFixr
Aug 11th, 06, 06:25 PM
Just updated. Took only a few minutes .
Thanks Jim!

Brian Lewis
Aug 11th, 06, 06:33 PM
Linux you have to update frequently as well. I know, I manage a ton of windows and linux servers all the time and there are security issues that come up all the time. Have to run 'yum update' just as often.

MrDanB
Aug 11th, 06, 10:37 PM
Thanks Jim (DH) K. ;)
Dano

Joe Harrison
Aug 11th, 06, 11:01 PM
Thanks!!

Vintage 68
Aug 11th, 06, 11:06 PM
Thanks Jim - done & done :thumbsup:

John M

cr8zy68
Aug 12th, 06, 12:54 AM
You're not not vulnerable to hardly any of these if you have a personal firewall... but definitely install updates ASAP as well as get a firewall or turn on the one in Windows. Some of these exploits require you to visit a malicious web site, so it pays to have a security solution in place like McAfee SecurityCenter.

Sassy8722
Aug 12th, 06, 10:59 AM
Thanks for sharing. :)

Al
Aug 16th, 06, 01:39 PM
ttt

Buck
Aug 18th, 06, 06:45 PM
Windows is heading in the right direction in regards to security. As Linux is used more in the desktop space and has a broader surface area that can be attacked, you probably see more exploits aimed at it as well. Right now the majority of Linux users are fairly computer literate which is something that can't be said for the Windows user based.
Linux you have to update frequently as well. I know, I manage a ton of windows and linux servers all the time and there are security issues that come up all the time. Have to run 'yum update' just as often.