PDA

View Full Version : some bad news.



ghost
02-15-2004, 09:34 AM
First, the remote DOS (denial of service) exploit has been published on the internet exploiting the MS04-007 vulnrability. It's only a matter of time before the black hats start using it.
Second and problably worse is the first exploit of the stolen win2k code has been published on an internet site. (from full disclosure).

Speedie Gonzales
02-15-2004, 08:28 PM
Just what does this break down into every day language?????In other words WHAT DOES IT MEAN????
Speedie

ghost
02-15-2004, 10:19 PM
I'll try to explain it w/o the sysop*****.
If you are running windows XS or Win2k. someone has developed a program that uses the most recent vulnrability that MicroSoft patched. He or She is gambling on most worldwide users have not installed the newest microsoft patch. this program attacks the "lsass.exe" file (the program that controls the security settings in windows versions listed above, and the current program is a DOS (deinal of service) attack. The program has been released to the internet and so far I have seen it available in nearly every country.

This past week someone managed to steal the source code for Windows 2000 professional operating system and is releasing it to just about anyone who wants it on the internet. What it means to the end user is the operating system most people use is very likely comprimised. Any flaw, (and there are many) in the windows operating system is now vulnrable to hackers/virus writers pretty much at will. What is worse is MicroSoft used much, if not all the same source code when they released Windows XP, therefore an exploit written for Windows 2000 will have a very good chance of working in Windows XP.