republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Arafat worm exploits new MS vuln
Search Topic:
Uniqs:
363
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
WSASRV? A WinSock Component or Something bad? »
« US company fined for UK rogue dialler scam  
AuthorAll Replies


Martinus
Premium
join:2001-08-06
EU


3 edits
reply to ironwalker
Re: Arafat worm exploits new MS vuln

said by ironwalker See Profile:

Arafat worm?

Must hide well and keep quiet...;)
Was supposed to be buried in a concrete coffin so he couldn't come back to haunt anyone.

Guess they should have wrapped him in tin foil too.
--
From the GSV "Ethics Gradient"


ironwalker
World Renowned
Premium,MVM
join:2001-08-31
Keansburg, NJ
clubs:
reply to John2g
Arafat worm?

Must hide well and keep quiet...;)


jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
reply to John2g
Fortunately, attachments and Arafat have 2 things in common. I don't like either so would never have a problem with this one in the first place. In my home they're both dead upon arrival.:D


John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England

»www.theregister.co.uk/2004/11/17···at_worm/

By John Leyden
Published Wednesday 17th November 2004 09:15 GMT
A worm which exploits curiosity about the death of Yasser Arafat is the first to exploit the known Extended MetaFiles vulnerability.

Aler is a network worm that was widely bulk-mailed with the subject "Latest News about Arafat!!!". These infected emails had two attachments, one a clean JPEG file and the other an infected EMF file, according to anti-virus firm F-Secure.

The EMF file exploits a well-known Windows vulnerability (MS04-032) to install the worm onto systems when the attachment is opened.

Thereafter, Aler spreads across network shares and hosts with weak user passwords. The worm's payload is a connection proxy that allows the attacker to initiate network connections through an infected computer. This feature could be used to send spam or attack other computers.

F-Secure rates Aler - which only infects Windows PCs - as a medium category nuisance. Standard precautions apply - vigilance about unsolicited messages, updating AV protection, use of stronger passwords, tin-foil hats etc. ®
--
Better to remain silent and be thought a fool, than to speak and remove all doubt.
Forums » Up and Running » Security » SecurityWSASRV? A WinSock Component or Something bad? »
« US company fined for UK rogue dialler scam  


Thursday, 26-Nov 02:32:27 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [105] New AT&T Ad Campaign Hits Back At Verizon
· [101] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [63] TiVo Sees Record Customer Losses
· [48] In-Flight Internet Headed For Bumpy Landing?
· [34] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [30] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· [DVR] DCX3400 - 30 Second Skip Forward [Comcast Cable TV]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]