microsoft blames security infosharing program for attack code leak
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today
Almaghrib Today, almaghrib today
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today

Microsoft blames security info-sharing program for attack code leak

Almaghrib Today, almaghrib today

Almaghrib Today, almaghrib today Microsoft blames security info-sharing program for attack code leak

London - Arabstoday

Microsoft on Friday confirmed that sample attack code created by the company had likely leaked to hackers from a program it runs with antivirus vendors. "Details of the proof-of-concept code appear to match the vulnerability information shared with Microsoft Active Protection Program (MAPP) partners," Yunsun Wee, a director with Microsoft's Trustworthy Computing group, said in a statement posted on the company's site . "Microsoft is actively investigating the disclosure of these details and will take the necessary actions to protect customers and ensure that confidential information we share is protected pursuant to our contracts and program requirements," Wee added. Under MAPP, Microsoft provides select antivirus companies with technical information about bugs before Microsoft patches the flaws. MAPP is meant to give third-party security vendors advance warning so that they can craft detection signatures. Among the things Microsoft shares with MAPP members, according to a program FAQ , are "proof-of-concept or repro tools that further illuminate the issue and help with additional protection enhancement." The Friday acknowledgment by Microsoft was prompted by claims earlier in the day by Luigi Auriemma , the Italian researcher who reported the vulnerability in Windows Remote Desktop Protocol (RDP) in May 2011. Auriemma said that code found in a proof-of-concept exploit on a Chinese website was identical to what he had provided HP TippingPoint's Zero Day Initiative (ZDI) bug bounty program. His code was then used by ZDI to create a working exploit as part of the bounty program's bug verification work. ZDI then passed along information about the RDP vulnerability, including the exploit that used Auriemma's code, to Microsoft. According to Auriemma, the public exploit included the string "MSRC11678," a reference to a Microsoft Security Response Center (MSRC) case number, indicating that the leak came from Microsoft. ZDI denied it had been the source of the leak. "We're 100% confident that the leak didn't come from us, and Microsoft is comfortable with us saying that," Aaron Portnoy, the leader of TippingPoint's security research team and the had of ZDI, said in an interview Friday. Portnoy also described the chain of custody of Auriemma's code -- a specially-constructed data packet that triggers the RDP vulnerability -- from its May 2011 submission to ZDI to its inclusion in the concept exploit that ZDI provided Microsoft in August 2011 as part of a broader analysis of the vulnerability. The proof-of-concept exploit now circulating among hackers does not allow remote code execution -- necessary to compromise a PC or server, and then plant malware on the system -- but instead crashes a vulnerable machine, said Portnoy. The result: The classic Windows "Blue Screen of Death." Portnoy also echoed what Microsoft's Wee said of the similarity between the public exploit and Auriemma's code. "We can confirm that the executable [exploit] does have a packet that was part of what Luigi gave us," said Portnoy. Microsoft launched MAPP in 2008. The program has 79 security firm partners, including AVG, Cisco, Kaspersky, McAfee, Trend Micro and Symantec, as well as several Chinese antivirus companies. A full list of MAPP members can be found on this Microsoft Web page . On Friday, Wee did not say whether Microsoft had a list of suspects, but noted that all information it passes to MAPP partners was under a "a strict Non-Disclosure Agreement (NDA)." If the leak did originate with a MAPP partner, it would be the first ever for the program. Microsoft's MS12-020 update patches the RDP bug, and can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.

almaghribtoday
almaghribtoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

microsoft blames security infosharing program for attack code leak microsoft blames security infosharing program for attack code leak

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

microsoft blames security infosharing program for attack code leak microsoft blames security infosharing program for attack code leak

 



Almaghrib Today, almaghrib today Skincare PR Performance Full Year 2017

GMT 09:22 2018 Monday ,22 January

Skincare PR Performance Full Year 2017
Almaghrib Today, almaghrib today New hunt for flight MH370 gets under way

GMT 11:03 2018 Wednesday ,24 January

New hunt for flight MH370 gets under way
Almaghrib Today, almaghrib today Modern colorful bedroom renovation

GMT 10:57 2017 Thursday ,21 December

Modern colorful bedroom renovation
Almaghrib Today, almaghrib today Puigdemont candidate for Catalan president

GMT 13:56 2018 Tuesday ,23 January

Puigdemont candidate for Catalan president
Almaghrib Today, almaghrib today Turkey detains dozens more

GMT 10:47 2018 Wednesday ,24 January

Turkey detains dozens more

GMT 09:56 2016 Wednesday ,23 March

cartoon one

GMT 10:20 2016 Wednesday ,23 March

cartoon ten

GMT 10:22 2016 Wednesday ,23 March

cartoon thirteen

GMT 10:18 2016 Wednesday ,23 March

cartoon seven

GMT 10:19 2016 Wednesday ,23 March

cartoon nine

GMT 10:17 2016 Wednesday ,23 March

cartoon six

GMT 10:24 2016 Wednesday ,23 March

cartoon fifteen

GMT 09:58 2016 Wednesday ,23 March

cartoon three

GMT 10:21 2016 Wednesday ,23 March

cartoon eleven

GMT 10:16 2016 Wednesday ,23 March

cartoon five

GMT 10:23 2016 Wednesday ,23 March

cartoon fourteen

GMT 10:22 2016 Wednesday ,23 March

cartoon twelve

GMT 10:18 2016 Wednesday ,23 March

cartoon eight

GMT 09:58 2016 Wednesday ,23 March

cartoon four

GMT 19:08 2012 Friday ,21 September

Nancy devotes album to youth

GMT 19:22 2015 Sunday ,26 April

Monaco take big step towards Champions

GMT 21:40 2017 Tuesday ,14 February

Tunisia Parliament Speaker meets Yemeni FM

GMT 09:47 2011 Wednesday ,30 November

Rise of the Muslim Brotherhood
Almaghrib Today, almaghrib today
 
 Almaghrib Today Facebook,almaghrib today facebook  Almaghrib Today Twitter,almaghrib today twitter Almaghrib Today Rss,almaghrib today rss  Almaghrib Today Youtube,almaghrib today youtube  Almaghrib Today Youtube,almaghrib today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2025 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2025 ©

.almaghribtoday .almaghribtoday .almaghribtoday .almaghribtoday
almaghribtoday almaghribtoday almaghribtoday
almaghribtoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
almaghribtoday, Almaghribtoday, Almaghribtoday