SecurityRatty :: tag: exploit
Featured Articles :: Exploit code loose for six-month-old Windows bug :: Massive RealPlayer Exploit Embedded Attack :: The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit :: MDAC ActiveX Code Execution Exploit Still in the Wild :: Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications :: America's Dilemma: Close Security Holes, or Exploit Them Ourselves :: New DNS exploit now in the wild and having a blast :: Months-old Excel exploit goes public :: Office exploit hits the street :: New exploit targets corporate CA users
Microsoft has acknowledged that exploit code is circulating for a still-unpatched vulnerability it first reported six months ago. But it's not clear when, or if, it plans to release a patch
...exploit before the vulnerability became public
One of our readers noted that there are a number of state government and educational sites that appear to have been compromised with the uc8010 domain. Upon review, I see that some of these have already been cleaned up. However, the .gov and .edu sites are only a few of the many many sites...
...exploit within a (random) copy of a popular web malware exploitation kit? Now that's interesting given that there are other modified versions of the publicly available malware kit empowered with exploits as they get released, the single most logical move a administrator of such kit would do is diversity the exploits set as often as possible,...
...exploiting CVE-2006-0003 , and despite that it was patched in 11 April, 2006, the last quarter of 2007 showcased the malware authors simplistic assumption that outdated but unpatched vulnerabilities can be just as effective as zero day ones, and when the assumption proved to be true -- take Storm Worm's use of outdated vulnerabilities as the...
The automatic patch-based exploit generation problem is: given a program P and a patched version of the program P', automatically generate an exploit for the potentially unknown vulnerability present
...exploit the same vulnerabilities and use the same techniques as criminal attacks against corporate networks. Internet worms make the jump to physically-separate classified military networks in less than 24 hours, even if those networks are physically separate. The Navy Cyber Defense Operations Command uses the same tools against the same...
A new hack designed to exploit a weakness in the DNS protocol is out, just days after information on the exploit was accidentally posted online. A patch for the issue was released almost two weeks ago, but a significant number of servers are still vulnerable
An exploit that targets a flaw in multiple versions of Microsoft's Excel software is now widely available, prompting Symantec to urge customers to apply a fix for the vulnerability released last week