Immunity launches exploit for 'unlikely' Windows worm hole

A workable exploit attack for a TCP/IP vulnerability in Microsoft's Windows has been launched into the wild courtesy of security firm Immunity.

On Jan. 17, it became clear that you shouldn't dawdle on deploying Microsoft's MS08-001 patch. That patch, issued Jan. 8, fixed a Transmission Control Protocol/Internet Protocol (TCP/IP) processing vulnerability that was critical for XP and Vista. After security firm Immunity issued a proof of concept, Microsoft acknowledged the vulnerability, but said an attack was "unlikely."

With Microsoft's assessment it basically threw down the gauntlet. A few days later Immunity is at it again--this time with a workable exploit.

Immunity ships exploits for its paying subscribers has issued a flash movie detailing the exploit in action. It isn't 100 percent reliable, but the odds are better than unlikely now.

Here are a few screens from the movie:




Your turn Microsoft. Ryan Naraine has more.

  • lol

    "Microsoft acknowledged the vulnerability, but said an attack was 'unlikely.'"


    Some things in life may be statistical, but a hacker taking advantage of a vulnerability isn't one of them. If it's possible, they'll do it, guaranteed.
    • Exactly

      Unless you have proof that it's not exploitable, assume it is. Someone is always better than you, and you aren't going to see all the possible ways something can be broken.
      • Unless...

        ...the so-called "security" firm wanting their day in the sun gets P.O.'d about it and decides to release it itself. The flaw WAS initially patched as a "critical" defect. Blame Redmond all you want, but ultimately BLAME for any of this getting out in the wild goes backs to the irresponsible nimrods at Immunity who think they are above responsibility. They found this flaw, reported it, got it patched by the vendor, then they still release the code anyways.

        So we now [i]know[/i] who's at fault here if a major breakout occurs. Pity the class-action types that Immunity probably doesn't have any sort venture capital or deep pockets lying around. Then again, they could probably go after Redmond for "callous dismissal of Immunity's claims".
  • RE: Immunity launches exploit for 'unlikely' Windows worm hole

    Wow! Windows has an exploit? One that is exploitable? Really??? No way! Not the "great Microshaft" that we have all come to know and hate!

    Come on Microsoft! If there is a will there is a way -- goes the saying and there is plenty of will and Microsoft has the way... so unlikely??? No!
  • exploit works locally and on winxp only

    exploit works locally and on winxp only.
    • Yeah ... for now ... (NT)

  • RE: Immunity launches exploit for 'unlikely' Windows worm hole

    OK, so all laughing asside, why are non of you indignant that a supposedly legit company has released an exploit into the wild? I can understand you expecting that some "hacker" will try the exploit but why is a supposed legit security company doing so, except, maybe to pad it's own pockets. I have to wonder whose interest they are working for. I figure that the more scare they throw out there, the more money they stand to make as people pay for security. They have an inherent conflict of interest in this. They are the ones you should be outraged about.
    It's like if someone discovered that a certain kind of house lock was easy to pick and started handing out the instructions to everyone on the street. don't start yelling at the lock company, however at fault they may be, they cannot take all the blame when your house gets broken into. Admitedly, This senario would be quite rare because physical devices don't spread as quickly as information on the Web does but it's the same thing.

    We should be calling for the head (theoreticallY) of the company who allows such a thing to be released, not laughing at all the poor saps who get caught and robbed because of it or blaming the lock company (MS in this case) because of a fault in their product.

    Your indignation needs to find the real targets. The people who are actually doing the damage and/or facilitating them. Nothing is ever really secure so stop whining and expecting that it should be.
    • You're missing the critical difference

      House locks, being physical items, are difficult to change. But this faulty code is information. All Microsoft has to do is patch this and ship it over Windows Update, and the hole's as good as gone. If they refuse to do that when it's been demonstrated that a flaw exists in their code, then they are responsible for leaving their users open to attack.

      Any damage caused by Immunity releasing the exploit details is more perceived than real, because hackers would have found this problem anyway, and they certainly wouldn't have shared the details of how they were breaking into people's computers with Microsoft, leaving the patch-writers at a disadvantage. It's a question of a little bit of trouble now, or a [b]lot[/b] of trouble further down the road.
      • Well...

        I'd have preferred if they (immunity?) had released a work-around with the "exploit." That'd have a lot more integrity to it all. I am so tempted by a car analogy but I have resisted the temptation :P
      • Microsoft has released a patch

        So indeed, the "hole's as good as gone."
  • Divulging an exploit:

    usually known by the high level hacker/cracker, but not necessarily to the novice or those who invest in exploiting them for financial gain, per say to increase a bot farm or info harvesting. The novice and the commercially corrupt may not have the same intel, . . . oops, but now they immunity . .
    • Forgot

      and yes, MS should do all that it can to wipe exploits out, especially divulged ones as it's like advertising a hot sale, come one come all, before the prices change. MS needs to role out fixes as critically fast as possible and stop the 'we don't believe' its a threat, treat it as if it were a great threat yesterday. . . . . Unless you're pro-actively blocking old spreadsheet and word processor file formats. Leave those only until someone else says they're vulnerable ;)
  • RE: Immunity launches exploit for 'unlikely' Windows worm hole

    Patch has been available since Jan. 8, 2008. If you're vulnerable, then there's nobody to blame but yourself.
  • ever heard of triage

    It happens everywhere. It's the process of trying to decide which "patients" are critical, which are lost causes and which can wait a while because nothing is going to happen in the immediate future. If I come to the emergency room and do something to screw up the triage process so that the decidsions made by the triage nurse is suddenly no longer valid. that doesn't mean his/her decision was Wrong, just no longer valid.
    In this case a decision was made based on the perceived risk. that decision is now not as valid as it may have been initially but that's beside the point.

    Immunity released the exploit to the wild so the hackers can use it immediately. Yes, some one eventually would have found it and figured out how to exploit it. But now, the don't have to "find it" and they don't even have to figure out how to exploit it. They just have to use the code that was released. The real evil behavior here is those people who released this code and of course the ones who use it. I'd say equal evil. there is no "good" use for releasing the code. The people at Immunity knew that no good could come from this. They should face some consequences.
