quarta-feira, 16 de junho de 2010

Miscreants Exploit Google-Outed Windows XP Zero-Day

URL: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/P12mhUxxSos/Miscreants-Exploit-Google-Outed-Windows-XP-Zero-Day


CWmike writes "A compromised website is serving an exploit of the bug in Windows' Help and Support Center, identified by a Google engineer last week, to hijack PCs running Windows XP. Graham Cluley, a senior technology consultant at antivirus vendor Sophos, declined to identify the site, saying only that it was dedicated to open source software. 'It's a classic drive-by attack,' said Cluley. The tactic was one of two that Microsoft said last week were the likely attack avenues. (The other was convincing users to open malicious e-mail messages.) The vulnerability was disclosed last Thursday by Google security engineer Tavis Ormandy, who also posted proof-of-concept attack code. Ormandy defended his decision to reveal the flaw only five days after reporting it to Microsoft. Cluley called Ormandy's action 'utterly irresponsible,' and in a blog post asked, 'Tavis Ormandy — are you pleased with yourself?'"

Read more of this story at Slashdot.


Nenhum comentário: