<<< Date Index >>>     <<< Thread Index >>>

Re: New AIM Expliot/Worm/Adware-script (realphx.com related)



As with the previous AIM exploit we saw, this one is just trying to use the
Object Data vulnerability variation.

MS03-040 was released last friday, fixing this variation.

http://www.microsoft.com/technet/security/bulletin/ms03-040.asp

As such, this is not trying to use any unpatched vulnerabilities and provided
that you are up-to-date on at least critical patches you are safe. The MS03-040
patch is one of those cumulative patches that all IE users should install
immediately, since it is a revised version of MS03-032 it fixes not only several
critical vulnerabilities (of which Object Data is just one) but it also fixes
all previously patched IE vulnerabilities. Consider it your starting point.


Regards
Thor Larholm
PivX Solutions, LLC - Senior Security Researcher
"Counterpoint: Linux vs. Windows Viruses" -
http://www.securityfocus.com/guest/23028
Service announcement - http://www.pivx.com/larholm/unpatched/


----- Original Message ----- 
From: "Michael A. Nunes" <p@xxxxxxxxxx>
To: <bugtraq@xxxxxxxxxxxxxxxxx>
Sent: Friday, October 10, 2003 4:19 PM
Subject: New AIM Expliot/Worm/Adware-script (realphx.com related)


> There appears to be some sort of a new AIM exploit/worm/adware-script that
> advertises the website www.realphx.com.  It sets people's AIM profiles to an
> advertisement for www.realphx.com and it also changes their default homepage
> in IE to the same thing.. I have no idea what *ELSE* it does.  I'm not
> qualified (what so ever) to figure out exactly what it is or how it works so
> I figured I'd send this along to the list and hopefully someone will have
> some expertise in this sort of thing.
>
> It appears to take advantage of the Windows Scripting Host or whatever its
> called.. anyhow you can get all the files that seem to be causing the
> infections right off the moron's website at: http://www.realphx.com/project/
> or http://64.246.11.26/~realphx/project/ or if the idiot happens to be
> subscribed to BugTraq I'll mirror the files @ http://shell.ltnx.com/realphx.
>
> Sorry for the lame format of this email and the lame content, I just can't
> stand to let AIM crap propagate around the Internet.
>
> --
> Michael A. Nunes
> /p at pcmike dot net
> http://pcmike.net/
>