[EMERGENCY] SMBv2攻撃コードが公開される
Posted in Announce, security on 9 月 30th, 2009 by gnome
まず、以下のOSのユーザ
Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2
Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
マイクロソフト セキュリティ アドバイザリ: SMB の脆弱性により、リモートでコードが実行される
SMBv2 Zero Day Exploit Code Publicly ReleasedThe good news is those who have tested the exploit claim it is only able to remotely execute code on vulnerable systems when those operating systems are run in VMware environments. If run on a physical machine, allegedly the public exploit code simply causes the machine to crash - admittedly a still-serious form of denial of service attack, but an improvement over remote code execution. If true, this lessens the likelihood of a wormable exploit (at least based on the code as it currently exists).
Windows SMB2 exploit now public; Expect in-the-wild attacks soonThe exploit, created and released by Harmony Security’s Stephen Fewer, provides a clear roadmap for hackers to plant malware or open backdoors on Windows Vista Service Pack 1 and 2 as well as Windows 2008 SP1 server.
US/CERTより再警告
Microsoft Releases Fix It for SMB Vulnerability日本語記事:
Windows SMB v2の脆弱性を突く新たな攻撃コードが公開 Microsoftの予想される反応:
所定の認証機関による脆弱性の発表ではないため、きわめて遺憾であり事実関係の確認を行っている最ちゅ・・・
クレーン
Microsoft、無料セキュリティソフトを間もなくリリース
Introducing Microsoft Security Essentials
IT史上の重大事件トップ10
JWordプラグイン インストーラーの検出について
米国税庁かたるウイルスメール、偽サイトには国内のゾンビPCも
IRSを騙るスパム3
tax-statement.exe received on 2009.09.28 13:10:06 (UTC)
the Information Warfare Monitor
WoWのトライアル・マウントにご用心
Data Center Security Cam recordings of 09.09.09 flood at Vodafone Istanbul, Turkey

Flash Player 10.0.45.2
KILL Acrobat JavaScript
Java 6 update 19
Apple QuickTime 7.5.6
Firefox 3.6.3
Chrome 4.1.249.1045
Opera 10.51
Thunderbird 3.0.4
O
OOo 3.2
RealPlayer SP1.1.2(12.0.0.641)
Skype 4.2.0.155
Pidgin 2.6.6
Wordpress 2.9.2
WireShark 1.2.7




Secunia PSI
MyJVN VerChk

BEFORE BURNER
