No content since 2004
Feel free to donate
Chris @ MyITforum
Subscribe in a reader
Subscribe to Chris Mosby at myITforum.com by Email
We are seeing the first Proof of Concept binaries that target the MS08-067 vulnerability on the following English localized systems:Windows XP Service Pack 2Windows XP Service Pack 3Windows 2003 Service Pack 2The payload is encrypted as normal. It's function is to add the guest account to the administrators group, thus allowing unlimited access to the machine. We detect the binaries as follows:Backdoor:W32/Agent.DINBackdoor:W32/Agent.DIOBackdoor:W32/Agent.DIPWe'll continue to keep an eye on the events.
No Comments