Hacker announces exposure of a vista vulnerability attack code

Source: Internet
Author: User

Hackers have publicly launched a new attack that exploits a severe security vulnerability in the Windows operating system.CodeTo force Microsoft to fix this vulnerability before the worm outbreak.

This security vulnerability was made public in September 7, but so far it has been exploited to attack computers.ProgramIn addition to causing system crash, you cannot do anything else. the attack code developed by Stephen fewer, a senior security researcher at Harmony, allows attackers to run fee-authorized software on computers. In theory, this security vulnerability has become a serious problem. fewer code was added to the open source metasploit intrusion testing tool on Monday.

Two weeks ago, a small company named immunity developed its own attack code using this security vulnerability. however, this code is only available to registered users of the company. in contrast, anyone can download the metasploit intrusion testing tool. this means that the attack code is now widely available.

Metasploit developer HD Moore said the security vulnerability code is effective in software such as Windows Vista SP1, SP2, and Windows 2008 sp1 server. This attack code can also attack windows 2008 SP2.

However, this attack code may not be completely reliable. kostya kortchinsky, a senior immunity researcher, said he could only use this metasploit to attack the Windows Vista operating system running in the vmwarevm process. when he runs the attack code on the local Windows operating system, this attack code can only cause system crash.

This attack code does not affect Windows XP, Windows Server 2003, or Windows 2000 operating systems. Windows 7 has fixed this security vulnerability.

Whether or not Microsoft will fix this security vulnerability when it releases a security patch in October 13 remains to be observed.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.