October 23, 2008 3:40 PM PDT

Microsoft RPC exploit could be a packaged deal

by Robert Vamosi
  • Font size
  • Print
  • 5 comments

While Microsoft has labeled Thursday's emergency patch MS08-067 as "critical" and provided a rareout-of-cycle fix because its exploit could easily be used as worm on a compromised network, one security researcher doesn't think it will happen that way.

"It's likely we're going to see this packaged with some other attack." said Ben Greenbaum, senior research manager at Symantec. "A Web-based attack, for example. We're looking out for are exploits of this being bundled with client-side exploits or Trojans so that the worm can get past corporate firewalls and get behind that firewall into the internal network."

Comparisons have been made to Zotob, an RPC worm that spread like wildfire in 2005. Remote Procedure Calls (RPC) allows programmers to run code either locally or remotely; a flaw within them is ideal for creating a worm.

"The potential is certainly there," Greenbaum said, adding that modern day attackers are "looking to create as much revenue for themselves as possible, and part of that equation means avoiding detection. What we're likely to see is that this will be added to a wide variety of attack tool kits already available."

"It's possible--but it's not likely--that we'll end up seeing a purpose-built worm that only exploits this one vulnerability," he said.

Since the patch came out Thursday morning, Symantec has seen increased scanning on ports 139 and 445, ports that exploits of MS08-067 would use.

There are some mitigating factors. Most firewalls, with default settings in place, should not allow an exploit of this penetrate that firewall, he said. However, home networks with File and Printer Sharing could fall victim to a bundled attack using this exploit.

The greatest danger is to systems running Windows XP and Windows 2000; Microsoft has ranked the patch as critical for these systems. On Windows Vista, Windows Server 2008, or Windows 7 pre-Beta, if the firewall is disabled, and File and Printer sharing enabled, an anonymous user could use this exploit to connect but would do so only at the lowest possible integrity setting, which would prevent successful exploitation, Greenbaum said. Microsoft has rated the patch only as important for those operating systems.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Security
Q&A: Researcher Karsten Nohl on mobile eavesdropping
RockYou sued over data breach
Hacker Gonzalez pleads guilty in Heartland breach
Microsoft rebuts IIS vulnerability claims
More attacks expected on Facebook, Twitter in 2010
GSM crypto code cracked, engineer says
Web-based Lookout protects mobile devices, data
Hackers claim to crack Kindle copyright armor
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by Vegaman_Dan October 23, 2008 6:37 PM PDT
They found an exploit and patched it immediately instead of waiting for a regular patch cycle. While I'm sure there will be those who will be quick to blast Microsoft for having the vulnerability, you have to give them credit for issuing a patch so quickly. There are other OS vendors out there that would never admit there was a vulnerability and issue a patch quietly or slip it into an unrelated product patch.
Reply to this comment
by The_Decider October 26, 2008 9:56 AM PDT
Too bad they sat on the blaster worm fix for 6 months.

One thing they did right doesn't erase years of incompetence. Let's wait and see if it is really fixed. More then likely it broke something and introduced a new hole.
by NTBugtraq-RussCooper October 24, 2008 8:04 PM PDT
Rob,

Ben's not the only researcher thinking the likelihood of a network worm is slim. We over at the Verizon Business RISK Team figure this will, like all malware these days, be used to line some criminal's pockets. We published our analysis to our blog yesterday...might want to keep and eye on it as we're going to try and get our analysis out in under an hour on future patches.

<a href="http://securityblog.verizonbusiness.com/2008/10/23/ms08-067-%e2%80%93-out-of-cycle-windows-patch/#more-151">SecurityBlog.VerizonBusiness.com analysis of MS08-067</a>

Cheers,
Russ
Reply to this comment
by The_Decider October 26, 2008 9:58 AM PDT
Since Symantec is a large virus writer I wouldn't put much stock in what they say.

Symantec is a virus because it takes complete control of your system and does crap like delete files without asking. It also turns itself back on if you disable something.
Reply to this comment
by fdunn3 October 27, 2008 4:05 PM PDT
This will no doubt be added to the MetaSploit Framework which is used PRIMARILY for penetration testing but also to the supposedly defunct (NOT) NeoSpoit framework for which you pay for your exploit.

So will there be a mass Internet worm? It depends on how stupid someone would be to let it loose.

Will there be targeted malicious releases? You bet. If there is money or intelligence to be had with this then it will be used in targeted attacks.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right