Redhat Posted December 30, 2004 Report Share Posted December 30, 2004 http://securityresponse.symantec.com/avcen...jan.phel.a.htmlTrojan attacking sp2 through html file. Quote Link to comment Share on other sites More sharing options...
Redhat Posted December 30, 2004 Author Report Share Posted December 30, 2004 Windows XP users Phelled by new TrojanBy Ashlee Vance in ChicagoPublished Thursday 30th December 2004 19:56 GMTA new Trojan horse - named Phel - that punishes users of Microsoft Windows XP operating system is in the wild.Security software firm Symantec has issued a bulletin warning Windows XP users to be on the look out for the program, which is distributed as an .html file. The malicious code can attack systems running XP Service Pack 2. The vuln was first found in October, and Microsoft is busy trying to catch up to it.Click Here"Microsoft is taking this vulnerability very seriously, and an update to correct the vulnerability is currently in development," the company told ComputerWorld. "We will release the security update when the development and testing process is complete, and the update is found to effectively correct the vulnerability."Symantec warns that users will see two Internet Explorer windows pop up when an .html file with Trojan.Phel.A is opened. If the code does its worst, the Trojan will automatically be executed every time a Windows user turns on his machine.http://www.theregister.co.uk/2004/12/30/ms_phel_vuln/ Quote Link to comment Share on other sites More sharing options...
Redhat Posted December 31, 2004 Author Report Share Posted December 31, 2004 Microsoft Internet Explorer XP SP2 Fully Automated Remote CompromiseAlthough hundreds of millions of dollars have been spent on securing SP2, perfection is impossible. Through the joint effort of Michael Evanchik and Paul from Greyhats Security, a very critical vulnerability has been developed that can compromise a user's system without the need for user interaction besides visiting the malicious page. The vulnerability is not actually a vulnerability in itself, but rather it is uses multiple known holes in SP2 including Help ActiveX Control Related Topics Zone Security Bypass Vulnerability and Help ActiveX Control Related Topics Cross Site Scripting Vulnerability.Vulnerable Systems:* Microsoft Internet Explorer 6.0* Microsoft Windows XP Pro SP2* Microsoft Windows XP Home SP2Proof of Concept:See a proff of concept of the above code at: http://freehost07.websamba.com/greyhats/sp2rc.htm* If an error is shown, press OK. This is normal.* Notice in your startup menu a new file called Microsoft Office.hta. When run, this file will download and launch a harmless executable (which includes a pretty neat fire animation)User Recommendations:* Disable HTA files* Disable Active Scripting in Internet Explorerhttp://www.securiteam.com/windowsntfocus/6B00O2KC0C.html Quote Link to comment Share on other sites More sharing options...
-pops- Posted December 31, 2004 Report Share Posted December 31, 2004 Do not get in a panic over this. From the Symantec site cited above:# Number of infections: 0 - 49# Number of sites: 0 - 2# Geographical distribution: Low# Threat containment: Easy# Removal: Easy Quote Link to comment Share on other sites More sharing options...
scuzzman Posted December 31, 2004 Report Share Posted December 31, 2004 404 - File Not FoundThe file either does not exist or this memberhas violated the Terms of Service and his account has been terminated.I think he got busted :( Quote Link to comment Share on other sites More sharing options...
Redhat Posted December 31, 2004 Author Report Share Posted December 31, 2004 I think an important point is that this vulnerability was discovered in OCTOBER and only now are MS bothering to patch. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted December 31, 2004 Report Share Posted December 31, 2004 I think an important point is that this vulnerability was discovered in OCTOBER and only now are MS bothering to patch.It's like a car recall...If cost to fix > cost from lawsuitsThere is no recall. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.