Universal Plug and Hack
By Davey Winder in Editorial
Posted in IBM on
My friends over at the IBM X-Force, the James Bond sounding research and development team that came along as part of the recent Internet Security Systems (ISS) acquisition have informed that they reckon we should be on the alert for a Microsoft Universal Plug and Play flaw to be exploited by the end of the week.
“Due to the ease of exploitation, we are taking this flaw very seriously” says Tom Cross, X-Force Researcher at IBM Internet Security Systems, continuing “however, since the UPnP service is not universally enabled in the corporate environment, it is unlikely that this flaw will result in a worm like Zotob.” The flaw in question allows a remote attacker to send a particular HTTP request to UPnP which will do the old buffer overflow trick and allow arbitrary code execution on the target system.
Of course, the point is that users of UPnP remain exposed unless and until patched, and we all know how slow many organisations are at rolling out such updates. If your security provider has not taken a pre-emptive approach to protecting its users, as IBM ISS has done, then you could be in trouble within a couple of days. My advice? Visit Microsoft and get patched now.
Make a comment
Tag cloud
Archives
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- Cuil frozen out: market share drops to next to nothing
20 comments
- Windows XP: the invincible OS
- Gatecrashing the WiFi hotspot party
- The 24 year old software that is still going strong
- Home workers are sick
- Big Brother Apple
- Spear phishing Catch 22 for Salesforce.com
- Dumbest phisher in history revealed
- Is BT misleading consumers with Option 2 broadband?
- Why ecommerce fails
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Betting on Hubdub technology (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Slowly slowly catchee Government IT monkey (100%)
- Who needs another set of web standards? (100%)
- The 6.5 billion quid hello (100%)

