September 17, 2003

New DCOM Exploit: It's HEEEEEEEERE!

Well, Bruce Schneier was the first to find a working exploit. Reports everywhere point to the fact that Bruce found the source code on a public website that virogen users frequent and has tested it in his lab at Counterpane.

If you didn't heed my warnings last week, perhaps NOW you will listen.

  1. Patch Your systems. Bring them up to date!
  2. Filter ports 135, 139 and 445
  3. Rethink your security strategy
The last one is the big one. If you even had to do 1 of the first 2 items, you need to reconsider your security policy. You should rethink your least privilege strategy and figure out just what services you REALLY need running on these machines.

Don't let the bastards win. If their attacks become futile, they will eventually grow tired and move on to something else.

Posted by SilverStr at September 17, 2003 09:22 AM
Comments

I'm guessing that this is separate from the 30 or so emails I've gotten in the last couple of days from "Microsoft security" with an attachement patch for IE that I should run.

Fuck microsoft.

Posted by: Arcterex at September 19, 2003 01:35 PM

You only had 30? I just got home from a 4 day holiday, and had 1970 that passed spamassassin.

Easy enough to nuke, but what a PITA.

Just so everyone knows, Microsoft NEVER sends a patch as an attachment in email en'mass. Never trust unsolicited email from someone appearing to be Microsoft.

Posted by: SilverStr at September 21, 2003 03:53 PM