internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Word Attack Hails from China
New and Un-Patched Vulnerability in Word Exposed
Ed Sutherland

If Microsoft Windows users need another reason not to open e-mail attachments, hackers are busy exploiting a zero-day vulnerability in Word 2002 and 2003.

Hackers are using a new and un-patched vulnerability in Word to create a Trojan posing as an official document from co-workers.

Once opened, Trojan.Mdropper.H installs a backdoor giving malicious hackers control of a Windows system, according to Symantec, one of the security firms warning users.

Microsoft said it will include a patch for the vulnerability June 13, as part of its usual monthly security notice release.

"So far, this is a very limited attack, and most of our antivirus partners are rating this as 'low,'" Stephen Toulouse, manager of Microsoft's Security Response Center program, wrote on the company's blog.

Noting a user would need to open the Word file for the exploit to work, the information "isn't meant to say the issue isn't serious," according to the blog posting.

The software company said it has been working with a "couple customers thus affected." However, Microsoft will investigate any variants it might find.

While Microsoft points to just a couple of customers hit by the Trojan, that could quickly change, according to security firm Secunia.

"Currently it appears that the vulnerability is only exploiting in small targeted attacks," said Thomas Kristensen, Secunia's CTO. However, it is certainly possible" to create an exploit released on a much broader scale, according to Kristensen.

How can users spot the Trojan? Microsoft's Toulouse says two common e-mail subject lines are "Notice" and "RE Plan for final agreement."

Microsoft is also recommending, along with using caution when opening e-mail attachments, that Windows users limit admin privileges.

But the SANS Institute believes Windows users should simply stop opening untrusted Word documents.

The exploit "almost certainly is from China," said Johannes Ullrich, SANS chief researcher.

While some believe the first report of this exploit being seen in the "wild" was at a Japanese government department, Ullrich said SANS bases its report on an attack of a U.S. defense contractor.

This is the first Trojan sent to a government agency that SANS can share with the public, although its received other reports, according to the researcher.

The attacks resemble those from a group of Chinese hackers known as "Titan Rain," the researcher told internetnews.com.

Zero-day vulnerabilities are not limited to new software, the SANS research said. "Sadly, even old software like Windows or Office still contains plenty of bugs to be found."

SANS, which earlier this month reported that zero-day attacks are on the rise, noted other shifts in software security, including a move away from usual targets and a decision to seek out security flaws that might be new and therefore less known.

"Hacking is not about getting your 15 minutes of fame anymore, Ken Durham, a director of rapid response for Dulles, Va.-based IDefense, told internetnews.com. "Cybercrime is a multi-million dollar global business."

News courtesy of internetnews.com

May 22, 2006

View All Anti-Malware Software

View All Anti-Virus Software

Contents:
1. New and Un-Patched Vulnerability in Word Exposed






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES