Zotob "o grande" - novo vírus

[TI]

Banido
Cuidem-se!

Monday, August 15, 2005 - 09:41 AM EST

"A new Internet virus has been detected that can infect Microsoft's Windows platforms faster than previous computer worms, said an anti-virus computer software maker. The ZOTOB virus appeared shortly after the world's largest software maker warned of three newly found 'critical' security flaws in its software, including one that could allow attackers to take complete control of a computer," Reuters reports.

"The latest worm exploits security holes in Microsoft's Windows 95, 98, ME, NE, 2000 and XP platforms and can give computer attackers remote access to affected systems, said Trend Micro Inc. 'Hundreds of infection reports were sighted in the United States and Germany,' Tokyo-based Trend Micro said in a statement released late last week. 'Since most users may not be aware of this newly announced security hole so as to install the necessary patch during last weekend, we can foresee more infections from WORM-ZOTOB,' it said," Reuters reports. Full article here.

"Zotob is not going to become another Sasser. First of all, it will not infect Windows XP SP2 machines. It also won't infect machines that have 445/TCP blocked at the firewall. As a result, majority of Windows boxes in the net won't be hit by it," F-Secure reports. "This worm replicates by scanning random machines at port 445/TCP. When a victim is found, the exploit code downloads the main virus file via ftp from the scanning machine, sets up ftp server on the infected machine and starts scanning for more targets." Full article here.
 
Se deixam a 445 aberta para o exterior, merecem ser contaminados. Seja este ou outro virus qualquer (por exemplo o Sasser).

Este patch saiu na terça-feira. É uma falha no PnP.
http://www.microsoft.com/technet/security/bulletin/MS05-039.mspx

Podem ver os outros patchs de agosto aqui:
http://www.microsoft.com/technet/security/bulletin/ms05-aug.mspx

O do IE / JPEG Image Rendering é bem mais perigoso:

JPEG Image Rendering Memory Corruption Vulnerability - CAN-2005-1988

A remote code execution vulnerability exists in Internet Explorer because of the way that it handles JPEG images. An attacker could exploit the vulnerability by constructing a malicious JPEG image that could potentially allow remote code execution if a user visited a malicious Web site or viewed a malicious e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
 
salvo erro, fiz win update um dia destes e ele instalou o patch
Security Update for Windows XP (KB899588), acho q é este
podem instala-lo manualmente, de qq forma é melhor ter uma firewall funcional pro q der e vier
 
[TI] disse:
"Zotob is not going to become another Sasser. First of all, it will not infect Windows XP SP2 machines. It also won't infect machines that have 445/TCP blocked at the firewall. As a result, majority of Windows boxes in the net won't be hit by it," F-Secure reports. "This worm replicates by scanning random machines at port 445/TCP. When a victim is found, the exploit code downloads the main virus file via ftp from the scanning machine, sets up ftp server on the infected machine and starts scanning for more targets." Full article here.

Se é verdade isto não vai ser um muito mau. Só mau:)
 
Back
Topo