main

Cybercrooks add Windows flaw to arsenal

Steven Parker   on 01 October 2006 - 13:06 · 11 comments & 4435 views

Advertisement (Why?)
Attackers have added another, yet-to-be-patched Windows flaw to their arsenal, experts warned Saturday.

Cybercrooks have started exploiting a flaw in the Windows Shell only days after sample attack code for the vulnerability surfaced. Web sites that exploit the vulnerability are popping up and attempt to load malicious software onto vulnerable Windows PCs in a way that is undetectable to users, experts said.

"There are professionals at work using the exploit code," security firm Websense said in an alert. The miscreants taking advantage of the flaw appear to be part of the same group that in December used another Windows flaw to hoist spyware onto PCs, Websense said. That flaw stemmed from the way Windows handled Windows Metafile, or WMF images.

Microsoft warned of the Windows Shell flaw on Thursday. The flaw affects Windows 2000, Windows XP and Windows Server 2003, and could be exploited via the Internet Explorer Web browser through a component called WebViewFolderIcon, the company said. Windows Shell is the part of the operating system that presents the user interface.

View: Full Story @ ZDNet

Post a comment · Send to friend Comments · There are 11 additional comments
(1 reply) #1 ThaCrip on 01 Oct 2006 - 13:13
firefox/opera users have nothing to worry about as usual
#1.1 Buttus on 01 Oct 2006 - 14:06
Quote - ThaCrip said @ #1
firefox/opera users have nothing to worry about as usual


I was just going to ask that!
(2 replies) #2 onlineravi on 01 Oct 2006 - 14:21
is there any loopholes in firefox ?
#2.1 Cryton on 01 Oct 2006 - 14:47
Quote - onlineravi said @ #2
is there any loopholes in firefox ?

Yes there is. Check out http://news.com.com/2100-1002_3-6121608.ht...8&subj=news
#2.2 RiVaLSSJ on 02 Oct 2006 - 03:36
Of course there are. No software is perfect.
#3 hairbautt on 01 Oct 2006 - 15:44
Ugh, more browser wars...

I'm an IE 7 RC1 User. FYI. No problems, got Outpost Firewall. Think I'm good to go
(1 reply) #4 Primetime2006 on 01 Oct 2006 - 17:09
IE7 is an excellent browser. So is Firefox. Hackers spend days, weeks, even months "finding" flaws in both brands of browser.

The fact is, they are not after the "average PC user", they are doing this for an ego boost and some credit. They are after the big businesses who don't secure themselves, the schools and institutions, not us.

Get a good firewall, both software and hardware if you want. Get a good A/V program and just watch where you surf and you'll generally be fine.

To say "Opera/Firefox users have nothing to worry about" when an IE flaw comes out and to say "IE users have nothing to worry about" when a Firefox flaw comes out is just stating the obvious. That is like me saying "Linux users have nothing to worry about" when they find a Windows flaw.

#4.1 RiVaLSSJ on 02 Oct 2006 - 03:35
Quote - Primetime2006 said @ #4
To say "Opera/Firefox users have nothing to worry about" when an IE flaw comes out and to say "IE users have nothing to worry about" when a Firefox flaw comes out is just stating the obvious. That is like me saying "Linux users have nothing to worry about" when they find a Windows flaw.

Well stated.
(1 reply) #5 toadeater on 01 Oct 2006 - 17:43
Internet Explorer Web browser

#5.1 RiVaLSSJ on 02 Oct 2006 - 03:36
What?
#6 scyphe on 02 Oct 2006 - 15:50
This is one of those times that makes me wonder why security experts release sample code of exploits on the internet.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)