AplusWebMaster
2007-03-26, 20:06
FYI...
- http://www.websense.com/securitylabs/alerts/alert.php?AlertID=758
March 26, 2007 ~ "Full exploit code was published this morning for MDAC vulnerability MS07-009. The original demonstration of this vulnerability occurred on July 29, 2006 in HD Moore's Month of Browser Bugs #29. At the time, only a denial-of-service demonstration was published... Our scanners are now actively searching for any live sites that are attempting to exploit this vulnerability. This type of vulnerability has been very popular with malicious attacks in the past and we expect to see its usage increase substantially, now that exploit code is publicly available. On February 13, 2007, Microsoft® released patch MS07-009 to address this vulnerability. We recommend that you apply this patch immediately, if you have not yet done so. See the Microsoft Security Bulletin at:
> http://www.microsoft.com/technet/security/bulletin/ms07-009.mspx ..."
Also noted here: http://www.us-cert.gov/current/#ADODBActiveX
:fear:
- http://www.websense.com/securitylabs/alerts/alert.php?AlertID=758
March 26, 2007 ~ "Full exploit code was published this morning for MDAC vulnerability MS07-009. The original demonstration of this vulnerability occurred on July 29, 2006 in HD Moore's Month of Browser Bugs #29. At the time, only a denial-of-service demonstration was published... Our scanners are now actively searching for any live sites that are attempting to exploit this vulnerability. This type of vulnerability has been very popular with malicious attacks in the past and we expect to see its usage increase substantially, now that exploit code is publicly available. On February 13, 2007, Microsoft® released patch MS07-009 to address this vulnerability. We recommend that you apply this patch immediately, if you have not yet done so. See the Microsoft Security Bulletin at:
> http://www.microsoft.com/technet/security/bulletin/ms07-009.mspx ..."
Also noted here: http://www.us-cert.gov/current/#ADODBActiveX
:fear: