Saint_Michael
May 13 2007, 05:23 PM
| | Although I am bit surprise that no one really take about way back then, but it seems the hackers and crackers I starting to use the microsoft update downloading to transmit there malware and torjans to compromised computers. The reason being is that the Microsoft update program bypasses firewall security protocals and so when that malware is getting download, your firewall and virus programs will not pick it up. I know a few people turn it off and either download them manually or don't download them at all. So to toss out a warning, when you get he windows update pop up check to see if those are legit files, by either going to microsoft's website and downloading the updates from there or look and read the update bulletins and see if they match up.
Source
Here
|
Reply
TypoMage
May 14 2007, 12:20 AM
Wow and my dad is always saying make sure to update and now it can not even be safe to update you Pc? Hmm that is kind of messed up?
Reply
jamers
Jul 4 2007, 02:54 PM
msscan.exe is part of one such trojan I'm dealing with recovery myself and I need some advice from an admin type guru before taking the destructive way out! I have server 2000 spk4 and after running trend micros "House Call" to do an online detection and clean up it found and removed all but the "Microsoft Security Update" (MSU) trojan, a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans (according to bleepingcomputer). Before running anything I wanted to stop some processes and try removing manually but my task manager was greyed out, (panic starts to set in). That's when I ran the house call... Then I booted into safe mode and deleted the directory for Microsoft Security Update and ran regedit to remove the MSU keys in both locations as listed by (don't remember the site name) manual removal instructions. OK, feeling better now the reboot and hmmmmm post beep, then pause then another post beep. This is strange, I don't recall having 2 posts but whatever. Wait for login and as soon as I press ctrl alt del the keyboard and mouse hang. Panic is back, feeling like this trojan is locking me out of my server so it can run some nasty mass mailer program or something. Tried booting into safe mode again but now the keyboard does nothing at any time during post. Can't get into safe mode, more panic. Tried booting into bios, can't get into bios, big panic attack. Can't boot from windows CD, don't have recovery disks or setup disks. Tried making them on my other box (win 98SE) but when booting the server with the setup boot disk I get disk IO error. Duh, too much panic I think maybe these disks can't be made on a 98 box and used to setup win2000 because of the different file system. So here I sit wondering if there is a way to get my server back without destroying all my data. I am willing to reinstall Windows if I can but would like to avoid having to install my apps again. When I boot the server with the ethernet disconnected there is an error starting a service... or something like that. One or more services failed to start.
Reply
75rLs3U4
Aug 11 2007, 11:12 PM
It's supposed it will happen. The talon d'Achille of Microsoft are the software that "dressed" his operative system. Microsoft has the concept that must fill the OS with software that emulates real antivirus and real firewalls to compete with other software creators. The problem is that left big holes that let hackers and attackers to take on assault not only the operative system, also the software, documents and everything that is inside of the computer. I was thinking when Bill Gates left the CEO, maybe the things change to make more strong the software to have a better Windows, Office and other stuff made by the Redmond boys. But, Mickey Mouse, they bet to still put more garbage instead of software and their systems get bigger and slower. Pretty, but very unusable for the people with old machines. And this is an advantage for hackers, crackers and other people that likes to found the holes left by the programming team of Redmond. So, I have an advise for they: the smaller: the safest. If they reduce the components to the core and stay there, will be more difficult to a hacker to found new holes in a smaller footprint operative system.
Reply
lilemi
Aug 11 2007, 11:37 PM
That's crazy, it's the last place I'd expect a hacker to come into your computer by: when my computer tells me to update I always allow it to automatically. My parents are always telling me to value updates over virus scans, because you need to be able to trap the newest viruses... How ironic is that? You download the latest updates to stop the latest viruses, and you get the latest viruses instead!  As long as McAfee updates don't have viruses though, I'm cool... McAfee is the best virus protection in my opinion and I would *hate* it if I never knew whether I was downloading a virus or virus protection.
Reply
Icarus
Sep 10 2007, 03:01 AM
Yeah I saw this on another site and didn't think much of it, till I realized the date of the article, and thought, "Oh crap, I might have downloaded it," and turned off Automatic Updates. Can anyone tell me the name of the malicious files? I don't think I'm infected, but I want to do a search for them just to make sure.
Reply
jamers
Sep 10 2007, 03:35 AM
QUOTE(Icarus @ Sep 9 2007, 11:01 PM)  Yeah I saw this on another site and didn't think much of it, till I realized the date of the article, and thought, "Oh crap, I might have downloaded it," and turned off Automatic Updates.
Can anyone tell me the name of the malicious files? I don't think I'm infected, but I want to do a search for them just to make sure. Well I know msscan.exe is part of a bad trojan.
Reply
Similar Topics
Keywords : microsoft update program hackers- Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read
- (8)
- Windows 7-windows Live Ties
- Microsoft is at it again (0)
In an internal memo Microsoft detailed how it plans to tie Win7 and Windows Live. It seems these
guys never learn. They don't don't get tired of monopolizing everything. I just pray the
anti-trust guys will do a good job on this one. Below is part of the blog by Mary Jo Foley about the
memo titled " Microsoft internal memo details Windows 7-Windows Live ties ": " In
January, I mentioned an internal Microsoft memo I had seen which provided details of how Microsoft
plans to more tightly integrate its Windows 7 operating system with Windows Live service...
Hackers Focus Efforts On Firefox, Safari, And Office
- (1)
QUOTE Many people are switching from Internet Explorer to alternative browsers such as Firefox
and Safari. Though that might make them feel more secure, the shift has also opened new doors for
bad guys. Case in point: We have no IE bugs to report this month, but both Firefox and Safari have
been hit hard. So forget the idea that just because you've switched to a new browser,
you're magically safer. You may be for a time, but to stay safe with any software, you need to
keep current with fixes. Firefox Holes In a somewhat dubious recognition of Firefox's...
Xp Sp3
- Has microsoft delivered. (5)
I am one guy who has always beleaved that when MS made XPsp2 they raised the standards for them
selves. the package was just too good for their own good. When Sp3 came out I didnt hesitate to
download it and what did I get? The first thing that i noticed was I could no longer use remote
desktop. i'm sure this has since been rectified in RC2 but it realy turned me off. I never
realised any gains in the SP. Still on the subject I found Adrian Kingsley-Hughes' blog titled
' XP SP3 performance gains - Nothing to write home about ' interesting He wrote: QU...
Best Anti-virus Program? [closed For Redundancy]
- (4)
I want to lnow which one is the best anti-virus program because i'm having serious problems
regarding all these viruses and spywares.So i want to know which is the best one around which i
should use...
Iphone Update Disable Hacked Phones
- (5)
After reading the article it is obvious what the update was for besides adding in new services and
updates, however, it took all of what, two weeks to hack the IPhone? So I doubt it will that long
to figure out what apple change to disable the hack phones. I found this particular quote amusing,
"...company officials insisted they were "not proactively" trying to make hacked iPhones useless."
Heck I would if I knew I would be losing millions of dollars a month on a phone that that was hacked
and used by another phone provider, but like I said earlier it won't take ...
Hole In Microsoft Messenger Program Requires A Immediate Update
- For Users of MSN Messenger 6.2, 7.0 and 7.5 versions of MSN Messenger (0)
SOURCE Well it seems that Microsoft found a huge hole in MSN Messenger that was bad enough that
they want people to upgrade to the current Messenger which is Live 8.1 or something like that. As
for details on the problem they just said the following, "..which let hackers embed malicious code
in Web chat invitations to users." and that they found this problem in "6.2, 7.0 and 7.5, as well as
Windows Live Messenger 8.0." Although it was interesting to know that people were actually
complaining about Live Messenger being a resource hog, well the last time I check msn w...
Myspace Has A Team Of Hackers
- (7)
I found this to be very interesting, a group of hackers routinly attack Myspace to find flaws and it
looks like they have already started finding them /laugh.gif" style="vertical-align:middle"
emoid=":lol:" border="0" alt="laugh.gif" /> I find it funny that they actually told Myspace that
they were going to do this, although I doubt they could find them anyways. /laugh.gif"
style="vertical-align:middle" emoid=":lol:" border="0" alt="laugh.gif" /> But again they already
found one which has to do with the url set up of which I won't post because of the legality o...
Phpbb Hackers
- LOL (21)
I got an email today: The following is an email sent to you by an administrator of "KORUPTION OWNZ
YOUR S****Y SITE". If this message is spam, contains abusive or other comments you find offensive
please contact the webmaster of the board at the following address: korupted@korupted.com Include
this full email (particularly the headers). Message sent to you follows:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Dear members. Your petty website has been hacked. The hacker's
name is Koruption. Next time dont use a outdated verison of phpbb b***hes So im a bit pissed off
and chec...
Mcafee Lets Users Download Rootkit Program For Free
- (2)
Since the beginning of 2007 a lot of the security reports I have been reading have mentioning about
hackers using rootkits to get into people's computers. Google defines a rootkit as a set of
programs used to hack into a system and gain administrative-level access. Once a program has gained
access, it can be used to monitor traffic and keystrokes; create a backdoor into the system for the
hacker's use; alter log files; attack other machines on the network; and alter existing system
tools to circumvent detection. Rootkits are an extreme form of System Modificatio...
Spammers, Hackers Seize On Virginia Tech Shootings
- (3)
Ok to me I consider the sickest form of human idiots ever, bad enough you have some people mocking
the shooter but now you got people using spam and hacking computers by using the Virginia Tech
shootings, This person should be found and beating for using a tragic event like this and trying to
profit from it. The spam/hack goes like this QUOTE If clicked, the link caused a computer to
automatically download a malicious screensaver, called TERROR_EM_VIRGINIA.scr by Sophos, which
installs a Trojan horse program that collects banking details, Cluley said. It was a...
Microsoft Rumor...
- From my Uncle. (17)
My uncle said Microsoft are going to be sending viruses out via Windows Updates, he said if you do
not have a genuine computer and you validate it you may get a virus. He said someone from PC World
told him. I'm not exactly sure so don't go crazy, but just to tell you it may be true, maybe
not....
Microsoft Windows Dhcp Client Service Remote Code Execution Vulnerability
- (0)
What it is A exploit in the buggy OS of XP has been found, this one concering DHCP. OS effected
Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows
2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced
Server SP4 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP3 Microsoft
Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Professional Microsof...
Microsoft Warns Of Virus Entering Pcs Via Powerpoint
- (3)
QUOTE Microsoft has alerted users of a virus that enters PCs through the PowerPoint program. The
virus attaches itself to a contaminated presentation that when accessed installs a keylogging
software on a computer. Users are being warned to take precautions because Microsoft patch that
guards against the security loophole will still be tentatively released on August 8. Reports say
the virus has infected relatively few people with the poisoned presentation. Malicious hackers used
the bug found in PowerPoint 2000, 2002 and 2003. Security experts report that the vir...
Microsoft Ships First Vista Security Patches
- yup, got that right -- VISTA (9)
Microsoft Ships First Vista Security Patches http://www.eweek.com/article2/0,1895,1911406,00.asp
QUOTE Microsoft Corp. has shipped the first critical security update for Windows Vista, the
next version of its flagship operating system. Over the weekend, the company released patches for
beta testers running the Windows Vista December CTP (Community Technology Preview) and Windows Vista
Beta 1, and warned that the new operating system was vulnerable to a remote code execution flaw in
the Graphics Rendering Engine. A Microsoft spokesperson told eWEEK that the Vi...
Microsoft Plans Free Anti-Spyware Program
- (12)
Stepping up its fight against computer threats at the risk of alienating security businesses,
Microsoft announced Tuesday it will give away a program to combat privacy-stealing and PC-clogging
spyware and other virtual pests.
Microsoft co-founder Bill Gates also unveiled plans to release
antivirus tools for consumers and make a major security upgrade to its Internet Explorer Web
browser. At the same time, he showed off new software for businesses to combat security threats.
The moves are part of a wide-ranging effort by the world's largest software maker to impro...
Firefox 1.5 Flaws
- For Microsoft User (22)
I got this information from mailing list. yesterday I didn't know why my pc always heavy to be
loaded. and now i got the answer read Firefox Flaws For A Simple Way. if you use Mozilla
Firefox 1.5 as your default browser. type Ctrl+Alt+del or open Task Manager. You will see how much
memory being used by firefox. QUOTE(www.informationweek.com) On December 8, 2005, we published
a story that wondered: Firefox 1.5: Not Ready For Prime Time? In response, some 450 (and climbing)
InternetWeek, InformationWeek, TechWeb Pipelines, and Scot's Newsletter readers ha...
Microsoft Plugs Windows Worm Holes
- 14 flaws in Windows... (3)
http://news.zdnet.com/2100-1009_22-5893344.html?tag=nl.e589 Here is another proof that the words
'Windows' and 'Security' simply cannot go together... And yet another good reason
for installing and start using Linux... Cheers! KoYoda...
[exploit] Microsoft Windows 2000 Plug And Play
- (1)
Microsoft Windows 2000 Plug and Play Universal Remote Exploit #2 (MS05-039) /*
HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2 * * Copyright © 2005 houseofdabus. * * (MS05-039)
Microsoft Windows Plug-and-Play Service Remote Overflow * Universal Exploit + no crash shellcode * *
.:: ::. * * --------------------------------------------------------------------- * Description: * A
remote code execution and local elevation of privilege * vulnerability exists in Plug and Play that
could allow an * attacker who successfully exploited this vulnerability to take * complete con...
[exploit] Microsoft Server Message Block
- (SMB) Remote Exploit (MS05-011) (0)
Microsoft Server Message Block (SMB) Remote Exploit (MS05-011) /* * Windows SMB Client
Transaction Response Handling * * MS05-011 * CAN-2005-0045 * * This works against Win2k * *
cybertronic gmx net * http://www.livejournal.com/users/cybertronic/ * * usage: * gcc -o mssmb_poc
mssmb_poc.c * ./mssmb_poc * * connect via \\ip * and hit the netbios folder! * *
***STOP: 0x00000050 (0xF115B000,0x00000001,0xFAF24690, * 0x00000000) * PAGE_FAULT_IN_NONPAGED_AREA *
* The Client reboots immediately * * Technical Details: * ----------------- * * The driver MRXSMB.S...
[exploit] Microsoft Internet Explorer Com Objects
- File Download Exploit (MS05-038) (0)
Microsoft Internet Explorer COM Objects File Download Exploit (MS05-038)
/*+++++++++++++++++++++++++++++++++++++++++++++++ Ms05 038 exploit POC Write By ZwelL 2005 8 11
http://www.donews.net/zwell zwell@sohu.com Some code belongs to Lion(cnhonker), regards to him.
This code tested on Windows 2003 -----------------------------------------------*/ #include
#include #pragma comment(lib, "ws2_32") // Use for find the ASM code #define PROC_BEGIN __asm
_emit 0x90 __asm _emit 0x90\ __asm _emit 0x90 __asm _emit 0x90\ __asm _emit 0x90 __asm
_emit 0x90\...
[exploit] Microsoft Windows 2000 Plug And Play
- Universal Exploit (0)
Microsoft Windows 2000 Plug and Play Universal Remote Exploit (MS05-039) /* Windows 2000
universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */
#include #include #include #include #include #include #include #pragma comment(lib,
"mpr") #pragma comment(lib, "Rpcrt4") BYTE Data1 =
{0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00,
0x30,0x00,0x30,0x00,0x30,0x00,0x30,0x00,0x00,0x0...
[exploit] Microsoft Windows Remote Desktop Dos
- (0)
Microsoft Windows Remote Desktop Protocol DoS Exploit (MS05-041) // Windows XP SP2
'rdpwd.sys' Remote Kernel DoS // // Discovered by: // Tom Ferris // tommy
security-protocols com // // Tested on: // Microsoft Windows XP SP2 // // Usage (SPIKE) :
./generic_send_tcp 192.168.1.100 3389 remoteass.spk 1 0 // // 8/9/2005 Security-Protocols.com // //
This program is free software; you can redistribute it and/or modify it under // the terms of the
GNU General Public License version 2, 1991 as published by // the Free Software Foundation.
s_block_start("packet_1...
Microsoft Windows Plug-and-play Exploit
- (0)
wow, you can get this famous vulnerabilty exploit here: http://www.milw0rm.com/id.php?id=1149
have fun /smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /> ...
Microsoft Internet Explorer "msdds.dll" Remote Cod
- Date : 17/08/2005 (1)
Take a look at this exploit! It's 0-day /tongue.gif' border='0'
style='vertical-align:middle' alt='tongue.gif' /> Advisory : FrSIRT/ADV-2005-1450 Rated as :
Critical Note : It is currently unclear whether the "Msdds.dll" library is installed with
Microsoft Office, Microsoft Visual Studio, or with other applications. More information will be
provided when further details are available. #!/usr/bin/perl
####################################################### # # Microsoft Internet Explorer "Msdds.dll"
Remote Code Execution Exploit (0day) # # Bindshell on...
Microsoft Windows Plug-and-play Service Remote Ove
- (3)
This is the c code you can compile it with lcc win 32 or gcc or virtual c++ ... /* Windows 2000
universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */
#define WIN32_LEAN_AND_MEAN #include #include #include #include #include #include
#include #pragma comment(lib, "mpr") #pragma comment(lib, "Rpcrt4") BYTE Data1 =
{0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00, 0x30,0x00,...
Microsoft Internet Explorer Javaprxy.dll Vul.
- (5)
Internet Explorer allows users to utilize Windows's COM Objects. A vulnerability with
javaprxy.dll allows attackers to craft a special HTML code that will cause Internet Explorer to
execute a remote command by using one of Windows's COM Objects. u can find the patches here :
http://www.microsoft.com/technet/security/...n/MS05-037.mspx also i just posted the exploit link
here for educational perposes : http://www.frsirt.com/exploits/20050702.ie...yexploit.pl.php ...
Another Firefox Security Update
- Firefox v1.0.3 (6)
Yes, another update. You can read the fixes at ZDNet or here at the Mozilla Release Notes .
Before installing v1.0.3 make sure that the directory you've chosen to install into is clean and
doesn't contain any previous Firefox installations! (known issue) Greetz, Rik©...
Windows Update Email Scam
- its a trojen horse (8)
QUOTE A new scam by hackers has some people believing they are receiving an e-mail about a
critical update to Windows when in actuality they are installing a Trojan horse, Sophos said on
Friday. The e-mail directs victims to a fake version of the Windows Update site, where there are
links to download the malicious "patches." "The email uses the Microsoft branding and style so to
the casual observer it appears to be legitimate," Gregg Mastoras, Senior Security Analyst at Sophos,
told BetaNews. If users download the "patches," they are actually installing the Troj/DS...
Firefox Security Update (firefox 1.0.2)
- Released 23-03-2005 (14)
Yesterday Mozilla (foundation) released another security update for Firefox. QUOTE(Mozilla
Foundation) March 23, 2005, (Mountain View, CA). The Mozilla Foundation, a non-profit organization
dedicated to preserving choice and promoting innovation on the Internet, today announced a security
update for its Firefox Web browser. The update is a proactive security release to patch a bug
identified by Internet Security Systems, a premier security research, products, and services
company. No known exploits of the bug have been reported prior to the update's release. ...
Looking for microsft, update, program, hackers
|
|
Searching Video's for microsft, update, program, hackers
|
advertisement
|
|