<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Microsoft warns of new attack on Word in Security</title>
<link>http://www.dslreports.com/forum/r20211036</link>
<description></description>
<language>en</language>
<pubDate>Sun, 20 Jul 2008 04:57:43 EDT</pubDate>
<lastBuildDate>Sun, 20 Jul 2008 04:57:43 EDT</lastBuildDate>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20264041</link>
<description><![CDATA[<A HREF="/useremail/u/1479210"><b>SilverSurfer</b></A> : <div class="bquote"><small>said by  caffeinator <A HREF="/useremail/u/1141361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Yet those MSJet files are still there. Why? I have no idea.<br><br> </div>you might want to get a processor identifier like the free kind from winternal or whatever it's name is, I can't recall at the moment.  it may help you ID whatever MSJ is doing. <br><br>the only other thing I can see the MSJ file coming into play for is if you attempt to download from MS any kind of template.  I did that the other day because I couldn't find any decent 28 line pleading paper templates for OO.  MS had one, but it first had to check my system before it would even think about letting me look at it.  When it couldn't find Word, it brought me to a manual download screen for the template and then I just modified it to writer.  Works great now.   :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20264041</guid>
<pubDate>Tue, 01 Apr 2008 13:42:55 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20260288</link>
<description><![CDATA[<A HREF="/useremail/u/1141361"><b>caffeinator</b></A> : I agree with you and  jouno53 <A HREF="/useremail/u/1335606"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, but when I bought this used machine I did remove Office from this computer. <br><br>Yet those MSJet files are still there. Why? I have no idea.<br><br>Is something still needing them? If so, then why like most any Installer since 1998, did it not ask if I wanted them still as they may be in use?<br><br>Apparently, since it was used at 2am yesterday. <br><br>[att=1]<br><br>I was asleep so what app used it? WinDefender? MSupdate?<br><br>I have yet to find any way of removing Jet on it's own except just deleting the files, which obviously is a bad plan. Manual removal you say? Nope..check this: &raquo;<A HREF="http://support.microsoft.com/kb/q124902/" >support.microsoft.com/kb/q124902/</A><br><br>The computer came with no disks, no restore partition, nada. So, how?<br><br>More to my point, since I'd removed Office, naturally MS won't see fit to offer an update for the leftovers.<br><br>I don't see a real risk to me, as I don't even use a mail client on the PC, nor am I click-happy. Fact is, exe/doc/xls/etc. are blocked by my mailserver unless you Zip them.<br><br>BUT, I resent having this trail of acknowledged insecure crap left on this otherwise perfectly functional computer. You'd think the almighty Microsoft could create a un-installer that worked.<br> <br>Since the workaround does nothing here, according to MS, I should just let it be...or upgrade to Vista. Ha! <br><br>With a P3-1Ghz/512Mb RAM Optiplex GX-150, that'd work really swell.<br><br>I swear, if I didn't need a windows PC for some things, I'd DBAN the ****** and install anything else.<br><br>Bleh.  :hmm:<br><br>-CaFF <br><small>--<br><br><A HREF="http://www.darkgrid.com/tribute/">My 9/11 Tribute</a>..online since 9/14/01 <br>Need an Avatar? Check out <A HREF="http://www.darkgrid.com/wafen/">Wafen's Avatar Pages</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/20260288?c=1292591&ret=L2ZvcnVtL3IyMDIxMTAzNi54bWw%3D"><IMG TITLE="46378 bytes" BORDER=0 WIDTH=367 HEIGHT=502 SRC="/r0/download/1292591~c2baf68500382c968465d6639a6f10a0/msjet.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20260288</guid>
<pubDate>Mon, 31 Mar 2008 20:25:35 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20260100</link>
<description><![CDATA[<A HREF="/useremail/u/1479210"><b>SilverSurfer</b></A> : That's why I use OO "Writer."  None of this kind of BS. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20260100</guid>
<pubDate>Mon, 31 Mar 2008 19:42:46 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20260068</link>
<description><![CDATA[<A HREF="/useremail/u/1335606"><b>jouno53</b></A> : Thanks for the info.<br><br>But that's why I use OpenOffice]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20260068</guid>
<pubDate>Mon, 31 Mar 2008 19:37:56 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20259601</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Someone else will have to help you deal with cleaning up an  infected machine. <br><br>(For myself, if I ever suspected an infection, I would reformat and start over)<br><br>Once you are sure it's clean, there is no reason why she can't resume on-line banking. You might review security measures with her. <br> <br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20259601</guid>
<pubDate>Mon, 31 Mar 2008 18:10:52 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20259532</link>
<description><![CDATA[<A HREF="/useremail/u/119587"><b>lotusracer</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  lotusracer <A HREF="/useremail/u/119587"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>How can I determine if the file was 'infected', </div><br>Since most of these exploits drop an executable, run the file in a test environment to see what happens.<br><br>I've not been able to get the PoC examples to work, so I would like to see the file you have.<br>----<br>rich<br></div>Thank you for your assist... checked with her and she must have completely deleted the file.  Looked around for it myself and found nothing.<br><br>Like caffeinator said in his case,  I tried the workaround and got the same error message saying it can't find echo.<br><br>What would be your suggestions on dealing with this potentially compromised machine?  Should I suggest she no longer do on-line banking, or suggest a complete re-format of this XP system?<br><br>Or is there some program in particular that can tell me if she has indeed 'oops'ed' her machine.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20259532</guid>
<pubDate>Mon, 31 Mar 2008 17:59:30 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20257468</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  lotusracer <A HREF="/useremail/u/119587"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>How can I determine if the file was 'infected', </div><br>Since most of these exploits drop an executable, run the file in a test environment to see what happens.<br><br>I've not been able to get the PoC examples to work, so I would like to see the file you have.<br><br><div class="bquote"><small>said by  lotusracer <A HREF="/useremail/u/119587"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Seems to be a lot of discussion on the possible danger, but none on how to deal with it.  Thanks for sharing any thoughts.</div><br>1) Be wary of Word files received unsolicited.<br><br>2) If sender is unknown, delete. If received from a known sender (as in your sister's case) open the file in a text editor, such as WordPad, which will not run code<br><br>3) Have White List protection which will prevent the installing of any unauthorized executable (see my first post above).<br><br>I estimate that in the past few years I've opened hundreds of Word files submitted by students, and from sites on the internet, with no worries.<br><br>  <br><br>----<br>rich<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20257468</guid>
<pubDate>Mon, 31 Mar 2008 12:00:21 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20256215</link>
<description><![CDATA[<A HREF="/useremail/u/119587"><b>lotusracer</b></A> : <div class="bquote"><small>said by  caffeinator <A HREF="/useremail/u/1141361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Interesting. Oh, and the workaround just throws an error saying it can't find echo.  Do I even need this stuff, and how can it be removed if I don't? I don't need all this detritus lying around waiting to be exploited.<br>-CaFF<br> </div>I've got a similar question.... my Sister, although being warned did open a Word file she received in an e-mail.  She "thought" she knew the person that sent it.  I may be able to upload the file from her computer if necessary.<br><br>How can I determine if the file was 'infected', and how best should I deal with this?<br><br>Seems to be a lot of discussion on the possible danger, but none on how to deal with it.  Thanks for sharing any thoughts.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20256215</guid>
<pubDate>Mon, 31 Mar 2008 06:46:46 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20232994</link>
<description><![CDATA[<A HREF="/useremail/u/1371265"><b>daveinpoway</b></A> : Somewhat scary: <br><br>No matter what kind of patch it produces or when it pushes a fix to users, Microsoft can't change the .mdb file format to make it less dangerous, according to Reavey. "Jet database files (file type .mdb) will remain on the unsafe file type list because they can run code by design," he noted. "Even if we tried to, we could not secure this file format, it will always present attackers an opportunity to run code."]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20232994</guid>
<pubDate>Thu, 27 Mar 2008 06:15:23 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20228849</link>
<description><![CDATA[<A HREF="/useremail/u/1141361"><b>caffeinator</b></A> : Interesting.<br><br>I had Office on this computer when first I got it, but later removed it since I never used it. However, I still have all the Jet files leftover. Argh.<br><br>Oh, and the workaround just throws an error saying it can't find echo.<br><br>Do I even need this stuff, and how can it be removed if I don't? I don't need all this detritus lying around waiting to be exploited.<br><br>-CaFF<br><small>--<br><br><A HREF="http://www.darkgrid.com/tribute/">My 9/11 Tribute</a>..online since 9/14/01 <br>Need an Avatar? Check out <A HREF="http://www.darkgrid.com/wafen/">Wafen's Avatar Pages</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20228849</guid>
<pubDate>Wed, 26 Mar 2008 14:03:07 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20228761</link>
<description><![CDATA[<A HREF="/useremail/u/151802"><b>jaykaykay</b></A> : "Do not open or save Word files that you receive from untrusted sources or that you receive unexpectedly from trusted sources," Microsoft said in a security advisory posted to its Web site late in the day." <br><br>"It thought users were safe, but is now scrambling for a solution"<br><br>This, of course, is so obvious but still so open to any hole in any program from MS or anyone else.  Social engineering has programmed humans to be all too much like Lemmings and we still, even knowing not to, open that which we shouldn't.  Not that that gives MS any excuse for not patching this hole which should have been done years ago, but since they've put what not to do in writing, they're played at CYA and exonerated themselves.  I wish my mistakes wee that easy to solve! :( <br><small>--<br>JKK:-)<br><br>Age is a very high price to pay for my maturity. If I can't stay young, I can at least stay immature! <br><br>&raquo;<A HREF="http://www.pbase.com/jaykaykay" >www.pbase.com/jaykaykay</A><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20228761</guid>
<pubDate>Wed, 26 Mar 2008 13:43:34 EDT</pubDate>
</item>

<item>
<title>Microsoft admits it knew about, didn&#x27;t patch, bugs</title>
<link>http://www.dslreports.com/forum/remark,20227932</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : From your link:  <blockquote><small>said by CW :</small><hr> Microsoft Corp.'s security team today acknowledged that it knew of bugs in its Jet Database Engine as far back as 2005 but did not patch the problems because it thought it had blocked the obvious attack vectors.<br><br>A researcher at Symantec Corp. said Microsoft should have fixed the flaws years ago.<br><br>In a post to the Microsoft Security Research Center (MSRC) blog <A HREF="http://blogs.technet.com/msrc/archive/2008/03/24/update-msrc-blog-microsoft-security-advisory-950627.aspx">late Monday afternoon</a>, Mike Reavey, the MSRC's operations manager, admitted that outside researchers had notified Microsoft in 2005 and 2007 of separate bugs in Jet, a Windows component that provides data access to applications such as Microsoft Access and Visual Basic.<br><br>In both cases, Microsoft told the researchers that it would not fix the flaw because it considered users safe.<hr></blockquote>Wrong.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20227932</guid>
<pubDate>Wed, 26 Mar 2008 11:11:12 EDT</pubDate>
</item>

<item>
<title>Re: Update</title>
<link>http://www.dslreports.com/forum/remark,20227855</link>
<description><![CDATA[<A HREF="/useremail/u/1371265"><b>daveinpoway</b></A> : Some new info regarding the problem: &raquo;<A HREF="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9071660&source=NLT_VVR&nlid=37" >www.computerworld.com/action/art&middot;&middot;&middot;&nlid=37</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20227855</guid>
<pubDate>Wed, 26 Mar 2008 10:57:22 EDT</pubDate>
</item>

<item>
<title>Update</title>
<link>http://www.dslreports.com/forum/remark,20218793</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Maarten Van Horenbeeck of sans.org has updated the diary I referred to:<br><br>Overview of cyber attacks against Tibetan communities<br>&raquo;<A HREF="http://isc.sans.org/diary.html?storyid=4177" >isc.sans.org/diary.html?storyid=4177</A> <br><br>You don't often find thorough analyses of attacks, so it's worth a careful reading.<br><br>This particular attack is described as "targeted."<br><br>The term Targeted has been used in a couple of ways in the security community:<br><br>1) attacks aimed at a particular group of people, such as the organization described in the diary; or, a company or corporation<br><br>2) those aimed at specific people in an organization. This requires compromising an email list.<br><br>This example uses both types of targeting.<br><br>While targeting has been used in the past, this example shows a sophistication in technique often missing: <br><br>==> A good command of the English language; <br><br>==> thoroughly researched details of the subject of world condition (Tibet in this case) which make the "social engineering" part of the exploit more convincing - here, including published articles in different formats (.doc, .pdf, .ppt) which embed the packed trojan. <br><br>Note that some victims have been home users.<br><br>Note again that use of a msjet40.dll exploit first surfaced in 2005.<br> <br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20218793</guid>
<pubDate>Mon, 24 Mar 2008 18:47:12 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20212915</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks for the additional info.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20212915</guid>
<pubDate>Sun, 23 Mar 2008 15:34:29 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20211036</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : This isn't the first time we've seen msjet40.dll exploited:<br><br>&raquo;<A HREF="http://ww3.ps-sp.gc.ca/opsprods/advisories/2005/AV05-020_e.asp" >ww3.ps-sp.gc.ca/opsprods/advisor&middot;&middot;&middot;20_e.asp</A><br>Advisory Number: AV05-020<br>Microsoft Jet DB engine vulnerabilities<br>15 April 2005<br><br><div class="bquote"><small>said by article   :</small><br><br>The purpose of this advisory is to bring attention a report of a vulnerability in Microsoft Jet Database Engine.<br><br>Microsoft Jet database is a lightweight database widely used by MS Office applications. The main component of the Microsoft Jet database engine is msjet40.dll,... Sufficient data validation is not performed when msjet40.dll parses the database file.</div><br>Also, from 2007:<br><br>&raquo;<A HREF="/forum/r19457987-ZeroDay-Microsoft-Access-Exploit">Zero-Day Microsoft Access Exploit</A><br><br>Quick: What does this exploit do?<br><br>From the code of the PoC:<br><br><textarea name="code" class="text" cols=50 rows=10>{Ph~&amp;#216;&amp;#226;sh&amp;#732;&amp;#254;&amp;#352;&amp;#14;W&amp;#255;&amp;#231;    calc.exe&#012;</textarea><!--end code block--><br>For calc.exe, substitute the latest and greatest trojan.<br><br>Evidently a patch has not been forthcoming. Microsoft's solution:<br><br>&raquo;<A HREF="http://www.microsoft.com/technet/security/advisory/950627.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;627.mspx</A><br><br><div class="bquote"><small>said by article   :</small><br><br>Suggested Actions&#9;<br><br>Protect Your PC<br><br>We continue to encourage customers to follow our Protect Your PC guidance of enabling a firewall, getting software updates and installing antivirus software.</div><br>(Question: Why isn't White Listing ever suggested?<br><br>Possible answer: because MS pushes AV solutions?)<br><br>For some insights in these types of exploits:<br><br>&raquo;<A HREF="http://isc.sans.org/diary.html?storyid=4177" >isc.sans.org/diary.html?storyid=4177</A><br><br><div class="bquote"><small>said by diary :</small><br><br>The attacks generally start with a very trustworthy looking e-mail, being spoofed as originating from a known contact, to someone within a community.<br><br>The messages contain an attachment which exploits a client side vulnerability. Generally these are:<br><br>CHM Help files with embedded objects;<br>Acrobat Reader PDF exploits;<br> <b>Microsoft Office exploits;</b></div><br>The handler who wrote this diary presented a paper (.pdf file linked in the diary) in which he analyzes the actions of the exploit:<br><br><div class="bquote"><small>said by paper   :</small><br><br>Application document<br>Exploitation Shellcode<br>Shellcode<br>Embedded executable Installs trojan code<br>or executesmalicious action</div><br>See page 10 of his .pdf paper for a nice diagram.<br><br>Often I can substitute a trojan file (not-white listed on my machine) to really test the exploit. This PoC, however, does not work on my Win2K machine. Here is an old one, a document with embedded trojan attempting to drop a .dll file:<br><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/dataRTF.gif"> <br>___________________________________________________________________________<br><br>Essentially, this is nothing more than a remote code execution exploit packaged in a different wrapper, easily blocked by White Listing.<br><br>The MS Security Bulletin offers a workaround to disable the offending jet.dll file. But what about the next exploit using another vulnerable file? And the next?<br><br>As suggested some years ago, White Listing removes the need for such workaround patching:<br><br>An Ounce of Prevention<br>&raquo;<A HREF="http://www.infosec.co.uk/ExhibitorLibrary/123/An_Ounce_of_Prevention.pdf" >www.infosec.co.uk/ExhibitorLibra&middot;&middot;&middot;tion.pdf</A><br><div class="bquote"><small>said by article   :</small><br><br>This approach can effectively eliminate the need to patch in emergency mode. Malicious code by default is not on the white list which means that enterprises can rest assured that their exposed software vulnerabilities are safe from potential exploitation, enabling their IT staff to work proactively to develop scheduled patch deployments rather than being in a constant state of emergency.</div><br>I've seen this approach used effectively in education institutions. Today, there are many home solutions available in the various security products providing execution protection, thus completely neutralizing this particular common exploit.<br><br>---------------------------------------------<br><br>Other references:<br><br>Microsoft Office Security, part one<br>Overview of recent MS Office vulnerabilities<br>&raquo;<A HREF="http://www.securityfocus.com/infocus/1874" >www.securityfocus.com/infocus/1874</A><br><br>&raquo;<A HREF="http://www.f-secure.com/weblog/archives/00001406.html" >www.f-secure.com/weblog/archives&middot;&middot;&middot;406.html</A><br>PDF file exploit:<br><div class="bquote"><small>said by article   :</small><br><br>The exploit silently drops and runs a file called C:\Program Files\Update\winkey.exe. This is a <br>keylogger that collects and sends everything typed on the affected machine to a server running at xsz.8800.org.</div><br>&raquo;<A HREF="http://www.avertlabs.com/research/blog/index.php/2008/03/11/social-engineering-tricks-use-tibet-to-lure-victims/" >www.avertlabs.com/research/blog/&middot;&middot;&middot;victims/</A><br>CHM (MS Help File) exploit<br><div class="bquote"><small>said by article   :</small><br><br>As the two cases looked similar (both drop a file named music.exe... drops and loads zipfldr.dl</div><br>Cyber Attacks Target Pro-Tibet Groups<br>&raquo;<A HREF="http://www.washingtonpost.com/wp-dyn/content/article/2008/03/21/AR2008032102605.html" >www.washingtonpost.com/wp-dyn/co&middot;&middot;&middot;605.html</A> <br><br><div class="bquote"><small>said by article   :</small><br><br>attached Microsoft Word document... included a Trojan horse program that opened a "backdoor" on any computer used to open the file, giving the senders remote access over the system.<br><br>Van Horenbeeck [of sans.org] said the danger with the e-mail viruses involved in the attacks is that they are so hand-crafted and new that they usually go undetected by dozens of commercial anti-virus scanners on the market today. <br><br>"Last week, I had two of these samples that were detected by two out of 32 different anti-virus scanners, and another that was completely undetected," he said.</div><br><br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20211036</guid>
<pubDate>Sun, 23 Mar 2008 05:24:44 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20208963</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Correction:<br>The following exploit caused my SAVCE(updated today) to quarantine"Trojan Horse"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20208963</guid>
<pubDate>Sat, 22 Mar 2008 18:43:59 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20208520</link>
<description><![CDATA[<A HREF="/useremail/u/957998"><b>NICK ADSL UK</b></A> : As posted here <br>&raquo;<A HREF="/forum/r20206292-Microsoft-Security-Advisory-950627">Microsoft Security Advisory (950627)</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20208520</guid>
<pubDate>Sat, 22 Mar 2008 17:12:00 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20208483</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Microsoft Jet DataBase Engine MDB File Parsing Remote Buffer Overflow Vulnerability<br><br>To exploit this issue, an attacker must entice a user into opening a malicious file.<br>&#9;<br>*Workarounds<br><br>Microsoft has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they help block known attack vectors. When a workaround reduces functionality, it is identified in the following section.<br><br>Restrict the Microsoft Jet Database Engine from running.<br><br>To implement the workaround, enter the following command at a command prompt:<br><br>echo y| cacls "%SystemRoot%\system32\msjet40.dll" /E /P everyone:N<br><br>*To undo the workaround, enter the following command at a command prompt:<br><br>echo y| cacls "%SystemRoot%\system32\msjet40.dll" /E /R everyone<br><br>Impact of Workaround: Any application requiring the use of the Microsoft Jet Database Engine to make data access calls will not function.<br>Microsoft Security Advisory (950627)<br>Vulnerability in Microsoft Jet Database Engine (Jet) Could Allow Remote Code Execution<br>Published: March 21, 2008:<br>&raquo;<A HREF="http://www.microsoft.com/technet/security/advisory/950627.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;627.mspx</A><br><br>The following exploit caused my SAVCE(updated today) to quarantine "Trogen.Horse"...<br><br>UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.<br><br>The following exploit is available. Symantec has not verified this exploit.<br><br>* /data/vulnerabilities/exploits/26468.mdb<br>&raquo;<A HREF="http://www.securityfocus.com/bid/26468/exploit" >www.securityfocus.com/bid/26468/exploit</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20208483</guid>
<pubDate>Sat, 22 Mar 2008 17:07:10 EDT</pubDate>
</item>

<item>
<title>Re: Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20208138</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Thanks for the heads-up.<br><br>From &raquo;<A HREF="http://www.pcworld.com/article/id,143749/article.html?tk=nl_d:xnws" >www.pcworld.com/article/id,14374&middot;&middot;&middot;l_d:xnws</A><br><br>"At this time, we are aware only of targeted attacks that attempt to use this vulnerability," the company [Microsoft] said. "Current attacks require customers to take multiple steps in order to be successful; we believe the risk to be limited."<br><br>Following its usual policy, Microsoft didn't say when -- or if -- it planned to patch the bug. But in a statement sent to the press, the company did not rule out the possibility of an emergency patch, released ahead of its next set of security updates, which are expected on April 8.<br><br>Users of many versions of Word, including Word 2007, 2003, 2002 and 2000 are at risk, unless they are running Windows Vista or Windows Server 2003, Service Pack 2. Those two operating systems include a newer version of the Jet Database Engine that does not have the bug, Microsoft said.<br><br>For the technically savvy: this means that PCs with a version of the Msjet40.dll that is lower than 4.0.9505.0 are vulnerable.<br><br>[Above pic from &raquo;<A HREF="http://support.microsoft.com/kb/239114" >support.microsoft.com/kb/239114</A> ]<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20208138?c=1289429&ret=L2ZvcnVtL3IyMDIxMTAzNi54bWw%3D"><IMG TITLE="27416 bytes" BORDER=0 WIDTH=485 HEIGHT=280 SRC="/r0/download/1289429~7d0bb59e34edf0f6c4e5939d9df4348b/jet.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20208138</guid>
<pubDate>Sat, 22 Mar 2008 15:49:19 EDT</pubDate>
</item>

<item>
<title>Microsoft warns of new attack on Word</title>
<link>http://www.dslreports.com/forum/remark,20208015</link>
<description><![CDATA[<A HREF="/useremail/u/1371265"><b>daveinpoway</b></A> : Read about it here: &raquo;<A HREF="http://www.pcworld.com/article/id,143749/article.html?tk=nl_dnxnws" >www.pcworld.com/article/id,14374&middot;&middot;&middot;l_dnxnws</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20208015</guid>
<pubDate>Sat, 22 Mar 2008 15:23:12 EDT</pubDate>
</item>

</channel>
</rss>
