Wednesday | 3 December, 2008
Russian hackers sold exploit, analyst says
Security vendor Kaspersky Lab says it appears two or three Russian hacker squads sold a WMF exploit for US$4,000.
Jeremy Kirk (IDG News Service) 06/02/2006 08:04:59

Security vendor Kaspersky Lab says that it appears two or three Russian hacker squads sold an exploit for the WMF (Windows Metafile) vulnerability that raised alarms in December.

Criminal gangs sold the exploit on specialized sites for US$4,000, wrote Alexander Gostev, senior virus analyst at Kaspersky, in a report on virus activity for the last three months of 2005. It appears someone discovered the vulnerability around Dec. 1, and exploit code emerged shortly afterward, Gostev wrote.

One of the purchasers of the exploit was involved in the adware and spyware business, Gostev wrote.

The WMF vulnerability was unique since no patch existed when it was publicly detailed, he wrote. Microsoft initially told customers around the end of December to wait for its monthly patch update in January, while security researchers warned the flaw could be used to steal data on infected machines and use those computers to send spam.

Security analysts also endorsed an unofficial patch created by programmer Ilfak Guilfanov. Microsoft ended up issuing a patch ahead of its regular schedule after critics argued the delay was giving hackers more time to work.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about Microsoft
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Achieving the impossible: Unlimited application scalability

Learn how provide applications with significantly higher throughput and lower latency for data operations while retaining the appropriate levels of data quality with clustered caching. Read on to improve your application scalability now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links