Hola a todos, navengando por hay encontré esto.... es de lavasoft (la empresa que hice ad-aware SE) y hay un parche para tapar el bug, me interesó pero no aparece mas informacion, solo entendí que el msn abre un back door (para que explicar que se puede hacer con un back door instalado) pero me interesa saber si este bug todavia esta vigente
Código:
or the typical user, having Messenger Service running opens an unnecessary "back door" that can compromise system security and which can be shut and locked tight easily. On October 15th of this year, Microsoft released Security Bulletin MS03-043 which outlines potential ways malicious programmers can exploit a flaw in the Messenger Service using buffer overflows to take control of your system. According to Microsoft, "An attacker who successfully exploited this vulnerability could be able to run code with Local System privileges on an affected system, or could cause the Messenger Service to fail. The attacker could then take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges." At this point, there are no known examples of malware taking advantage of this loophole, but it's almost certain that as this problem becomes more well known, attacks on systems vulnerable to this threat will occur.
Esta parte esta interesante.









Autor



En línea



