The Exploits Are A-Comin'
|
At Milw0rm, "cocoruder" has posted a remote exploit that's been successfully tested on Windows 2000 Server SP4 (Chinese).
Customers in Dave Aitel's Immunity Partner Program also have access to a fully-functional exploit for the MS06-070 bug.
It's a testament to the times we live in when exploits can be written and networks can be scanned for vulnerable hosts ten times faster than patches can be tested and deployed.
UPDATE: Ken Dunham, director of Verisign's iDefense Rapid Response Team sent this nugget via e-mail:
"iDefense has discovered that hackers originally discovered this the MS06-070 vulnerability a year ago but had initial difficulty in using it to trigger execution of code."
According to eEye, Microsoft shipped the patch 122 days after the flaw was reported on July 25, 2006.

