As we feared the MS12-020 bulletin from last black Tuesday caused a race for finding an exploit.
-- |
Swa 760 Posts Mar 16th 2012 |
Thread locked Subscribe |
Mar 16th 2012 9 years ago |
One of the interesting things about this is rdpclient.exe appeared on a Chinese file download website two days ago - before Luigi released his details. Yet it contains Luigi's packet capture. Hell, the executable even contains the string MSRC - Microsoft Security Research Centre - and the MSRC reference number of the issue.
Oops. |
Anonymous |
Quote |
Mar 16th 2012 9 years ago |
I didn't get a SMS when the infocon was raised to yellow, is that system still operational?
|
Anonymous |
Quote |
Mar 16th 2012 9 years ago |
Note that for Vista and later versions, it is possible to use group policy to centrally require Network Level Authentication which blocks the attack.
The path to the setting is computer configuration:policies:administrative templates:windows components:remote desktop services:remote desktop session host:security:require user authentication for remote connections by using..... Takes effect without a reboot, and obviously doesn't help with XP/2003 server machines, but it's often quicker to deploy a GPO than it is to deploy a patch and wait for an outage window to reboot, or rely on a user rebooting. |
Anonymous |
Quote |
Mar 16th 2012 9 years ago |
net-security has an article on the released code. It links to a Threatpost article from early this morning: http://www.net-security.org/secworld.php?id=12608
There are also quite a few recent stories on Google News: https://www.google.com/search?q=MS12-020&tbm=nws @baillard: I did receive an SMS at 10:15 CDT. |
Anonymous |
Quote |
Mar 16th 2012 9 years ago |
Where does one register for the INFOCON via SMS? I've looked and can't find it.
Also there wasn't a tweet to "SANS ISC Fast" about the INFOCONN status change, 2000+ follower's may still not know ![]() |
FTWMike 24 Posts |
Quote |
Mar 16th 2012 9 years ago |
@FTWMike: http://isc.sans.edu/notify.html
|
FTWMike 7 Posts |
Quote |
Mar 16th 2012 9 years ago |
Sign Up for Free or Log In to start participating in the conversation!