Bonjour à toutes et tous,
C'est quand même un comble d'avoir ce qui suit
dans le forum dédié à la sécurité....
no comment.. ha si en fait, si quelqu'un
pouvait me résumer l'explication qui n'est pas en
français...je lui en serait trés reconnaissant.
Merci à tous et bonne journée.
en tout cas, pas gentil de laisser traîner ce
genre de truc ici...
Rapport F-Secure du 13/12/04 14:45:26
D:\PROGS\mesnews\Serveur-3\
*fr.comp.securite.virus*\20041212-1.news
Infection: Exploit.HTML.Mht Action : Supprimé.
Exploit (generic description)
An exploit is a short code or script that uses a
vulnerability in a software or an operating
system to perform certain malicious actions. The
most famous exploit is called 'Incorrect MIME
Header exploit' or 'Iframe'.
The Incorrect MIME Header exploit allows to
automatically run an e-mail attachment on certain
unpatched versions of Microsoft e-mail and web
browsing software. This exploit is widely used by
famous e-mail worms - Nimda, Klez, Yaha, Bugbear,
Bridex and many others. When a recipient of an
infected e-mail only previews an infected
message, an infected attachment is activated by
the Iframe exploit and a computer becomes
infected.
Another exploit that is used by a widespread
Opaserv worm is the 'Share level password
exploit'. The Opaserv worm tries to bruteforce a
share password by selecting only a single
character for a password. In case the first
character of a password is correct, the
authentication process is be successfully
completed. As a result it is enough to try only
all one-byte passwords to get access to
password-protected shares.
Usually software vendors, whose software or
operating system is affected by exploits release
security patches that fix these vulnerabilities.
Most famous exploits: Incorrect MIME Header
(Iframe), Share level password exploit.