Spyware Sucks
“There is no magic fairy dust protecting Macs" – Dai Zovi, author of “The Mac Hacker’s Handbook"

MS08-067 is being actively exploited…

October 23rd 2008 in Uncategorized

Here is just one example:
http://vil.mcafeesecurity.com/vil/content/v_152898.htm

Threatexploit blog:
http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html

You’re patching, yes?

Watch out for crashes affecting svchost.exe and netapi32.dll.

ISC have raised their threat level to Yellow.

There are two more webcasts set up:

For the Thursday, 10/23/08, 5:00 PM Webcast, customers can register at:
http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032394183&Culture=en-US

For the Friday, 10/24/08, 11:00 AM Webcast, customers can register at:
http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032394179&Culture=en-US

A recording of the original webcast is now available:
http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032393978&EventCategory=4&culture=en-US&CountryCode=US

So far we know that the bad guys already using the vulnerability have been utilizing:

doradora.atzend.com (69.162.76.42)
perlbody.t35.com (66.45.237.219)
summertime.1gokurimu.com (59.106.116.229) (note: disog.org has mis-spelled this domain name)
59.106.145.58

Cite: http://www.disog.org/


Comments are closed.

  Here’s the Press Release:http://www.prweb.com/releases/2008/10/prweb1504344.htm An Esthost representative also posted a message to NANOG a while back – as far as I know, there was only one public response:http://www.gossamer-threads.com/lists/nanog/users/109300 Do I believe that Estdomains/Esthost are innocent victims?  Nah… too much has happened for too long.  Let’s not forge these Washington Post articles: Part […]

Previous Entry

I received this email today: “I bought a 64 bit HP PC with Vista Home Premium and ie7 installed. When I was at a website to view something today it said I needed an Adobe plugin and directed me to Adobe. But Adobe said it did not have a 64 bit version and […]

Next Entry

Archives