Another exploit - be careful, no hot fix yet - Philadelphia Conshohocken Delaware Valley PA USA
Netforcement Header
Spacer Services Security Resources Case Studies About Contact Us

Another exploit - be careful, no hot fix yet

01-12-04


(Philadelphia & Conshohocken, PA)

(Philadelphia & Conshohocken, PA) A Trojan horse program that appears to be a Microsoft Corp. security update can download malicious code from a remote Web site and install a back door on the compromised computer, leaving it vulnerable to remote control. IDefense Inc., a Reston, Va., computer security company, said the malicious code is the latest example of so-called social engineering to fool Windows users. It is similar to the W32Swen worm, which last year passed itself off as a Microsoft patch. “The success of Swen in 2003 encouraged virus writers to put effort into creating official-looking e-mails and Web sites,” said Ken Dunham, director of malicious code for iDefense. The Trojan arrives as an attachment to an e-mail that appears to be from Windowsupdate@microsoft.com. The subject line says, “Windows XP Service Pack (Express)—Critical Update.” The message describes the attachment, WinxpSp1.A, as a cumulative patch that corrects security flaws in versions of Microsoft Internet Explorer, Outlook and Outlook Express. It downloads an executable file that will open a TCP port to listen for remote commands from the attacker





BACK to the Netforcement News Page.

REQUEST MORE INFORMATION On how Netforcement can help you secure the integrity of your network.

 
Footer1
Home Page Customer Login PGP Keys