Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Support > Trojan writers are taking on Microsoft's patching cycle.

Reply
Thread Tools

Trojan writers are taking on Microsoft's patching cycle.

 
 
Au79
Guest
Posts: n/a
 
      11-14-2005
John Dunn, Security editor

November 11, 05
Tuesday will be zero day. One day.
Trojan writers are taking on Microsoft's patching cycle.

Only two days after Microsoft issued a patch for a “critical” flaw
related to the graphics rendering engine in Windows, Trend Micro has
unearthed a Trojan out to exploit it.

As it happens, the Troj_emfsploit.A (Trend’s name) does nothing worse
than cause the core Windows explorer.exe shell to crash, which is
merciful. The vulnerability could, according to Microsoft, have resulted
in an attacker taking complete control of any Windows 2000, XP
(including SP2) and Windows Server 2003 PC.

Anti-virus vendors are a miserable bunch, forever frightening us with
yet another dreadful portent. Anyone would think they profited from such
fear.

This one is significant, however, and could make those folksy-sounding
patch Tuesday bug patches Microsoft has turned into a monthly event a
good deal more tense in future.

How long before a major software company of the ilk of Microsoft faces
issuing a patch for a vulnerability that has already been exploited?
This is the so-termed “zero day” issue and the speed at which Trojans
are being cranked out now suggests this will happen soon, if hasn’t
happened already.

We could be about to enter a world of real-time patching, with periods
of vulnerability being measure in minutes rather than in days, as at
present. It is possible that the average enterprise with money to throw
at one of the legion of companies looking to provide real-time security
services, will be able to cope.

Can such a service be automated? Doubtful. Patches need to be tested if
they relate to core elements of the operating system or the services it
provides. This is always going to involve someone, somewhere scratching
their head and making a sensitive judgment.

Nobody in the early days of software could have forseen it, but code is
now evolving with a genetic fedundity not far short of a Drosphila fruit
fly. Security has done that to us.
--

http://www.euronet.nl/users/frankvw/...t/IhateMS.html
 
Reply With Quote
 
 
 
 
Noel Paton
Guest
Posts: n/a
 
      11-15-2005

"Au79" <> wrote in message
newsZ8ef.13851$...
> John Dunn, Security editor
>
> November 11, 05
> Tuesday will be zero day. One day.
> Trojan writers are taking on Microsoft's patching cycle.
>
> Only two days after Microsoft issued a patch for a “critical” flaw related
> to the graphics rendering engine in Windows, Trend Micro has unearthed a
> Trojan out to exploit it.
>
> As it happens, the Troj_emfsploit.A (Trend’s name) does nothing worse than
> cause the core Windows explorer.exe shell to crash, which is merciful. The
> vulnerability could, according to Microsoft, have resulted in an attacker
> taking complete control of any Windows 2000, XP (including SP2) and
> Windows Server 2003 PC.
>



TREND have revised their opinion of this exploit -
http://www.techworld.com/security/ne...SS&NewsID=4781

--
Noel Paton (MS-MVP 2002-2006, Windows)

Nil Carborundum Illegitemi
http://www.crashfixpc.com/millsrpch.htm

http://tinyurl.com/6oztj

Please read http://dts-l.org/goodpost.htm on how to post messages to NG's


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: "Win32:Trojan-gen. {VC}""Win32.trojan-gen.{UPX!}" jamesa01 Computer Support 2 02-27-2006 02:54 PM
"Win32:Trojan-gen. {VC}" "Win32:Trojan-gen. {UPX!}" D@Z Computer Support 5 01-30-2006 07:52 PM
New trojan spam tells you where to download trojan as "MS beta antispy" Joel Rubin Computer Support 2 03-07-2005 02:26 AM
Help! aspnet_wp not working after patching kb886903/kb886906! Edward Yang ASP .Net 6 02-18-2005 08:18 PM
Difference in module_eval taking block vs. taking string (1.8 bug?) Jim Cain Ruby 1 07-18-2003 02:01 AM



Advertisments