HZRN.COM
welcome to my space
X
Welcome to:hzrn.com
Search:  
NAVIGATION - HOME
Bugtraq List Accidentally Releases Malicious Code
Published by: cfz 2009-01-07
The first program that exploits a newly discovered hole in the popular BIND software has been posted to a public mailing list.

Source code to the program was posted anonymously to the Bugtraq security mailing list Wednesday night, just days after a division of Network Associates Inc. (NAI) warned network administrators of four serious new bugs in BIND, which is used by 80 percent of the domain name servers in use on the Internet.

According to Elias Levy, chief technology officer for SecurityFocus.com, publishers of the Bugtraq list, the program appears to successfully exploit a buffer overflow bug in BIND version 8. But in what appears to be a case of shooting the messenger, the exploit then launches a denial of service attack on a name server owned by Network Associates. For this reason, the program is considered to be a Trojan horse, and Bugtraq subscribers have been warning others on the list not to run the program.

Putty Changelog - OldApps.com Forum::
Jan 30, 2008 Security fixes: two vulnerabilities discovered by iDEFENSE, potentially allowing arbitrary code execution on an SFTP client by a malicious
http://www.oldapps.com/forum/showthread.php?t=552
HOME
Web Security - McAfee SiteAdvisor Hits 75 Million Download Mark::
Sep 12, 2007 Bugtraq: Endless loop and resources consumption in Halo 1.0.7.0615 browser to execute malicious JavaScript code within the security
http://www.bestsecuritytips.com/news+index.storytopic+9+start+25.htm
HOME
However, Levy said it's likely that some percentage of the list's 35,000 subscribers tested the program and unknowingly participated in an attack on the NAI DNS server. But he said the list's moderator did not err in letting the message with the Trojan go through.

"People when they subscribe to the list, it's with the caveat that they might be receiving exploits at some point or another, or some information, that is not fully fleshed out yet," Levy said. "We always recommend that they wait until other people analyze the information or the code itself to make sure it works as the poster claims."

LPI certification 102 (release 2) exam prep, Part 3::
List of all pages for LPI certification 102 (release 2) exam prep, Part 3 These include the security-conscious CERT and SecurityFocus' BugTraq list,
http://www.scribd.com/doc/15792/LPI-certification-102-release-2-exam-prep-Part-3
HOME
In fact, Levy said that someone from NAI's COVERT Labs reviewed the program before it was posted to Bugtraq and failed to notice the section of code that includes the attack on the company's server. Whether the code has been successful in slowing traffic to NAI's sites is not clear. Company officials were not available by news time, but the firm's Web sites appeared to be up at news time.

In any case, the incident illustrates what many feared -- that exploits of the BIND DNS bugs would follow closely on the heels of the publication of the bugs. And that means the race is on for system administrators to get their software patched.


helloNetwork.com to Challenge Mainstream Streaming Media
Bug Opens Microsoft IE to HTML .exe Attachments

You are looking at:hzrn.com's Bugtraq List Accidentally Releases Malicious Code, click hzrn.com to home
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about Bugtraq List Accidentally Releases Malicious Code , Please add it free.
  • where could i find a great program to teach volleyball for my sophomore age daughter
  • 4 2 volleyball rotation
  • what is that one lemonade drink that pro tennis players like nadal drink
  • are there any exercises that can help you with an overhand volleyball serve
  • how good do you have to be to play college tennis
  • what are your 2009 season slam predictions men women
  • surfing the southbay los angeles after rain
  • can i put a regular pool table outside
  • experiences with indoor volleyball outside winter
  • how to make a perfect volleyball spike
  • how do i complain about a pool cheat
  • how do you know when its your ball when you 039 re in a volleyball game
  • i 039 m too scared the next time i play tennis i 039 ll screw up again sorry i know it 039 s a long description

  • what is a good alternative to running
  • which is faster a grab start or a track start
  • does anyone have a surfer friend
  • volleyball conditioning training plan
  • i have a pool table question
  • what do you feel about surfing
  • how can i set the volleyball really well
  • how to improve volleyball skills for tryouts
  • isnt roger federer so lucky to finish as world no2 at yearend
  • next best tennis racquet
  • why are there cold spots in the ocean and also your pool
  • queuing for wimbledon tickets
  • i am training for a marathon but have found runs difficult since the time change how can i get motivated
  • can i use my tennis shoes on a volleyball court
  •  Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzrn.com        Site made:CFZ