OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] No one else seeing the new MS05-039 worm yet?

From: Peter Ferrie (pferriesymantec.com)
Date: Tue Aug 30 2005 - 16:14:41 CDT


...

>Lastly they don't point out that "worm" propagation based on the
>PnP vulnerability only occurs on the Win2K boxes. Win2K3 and
>WinXP require some user/machine action to exploit the
>vulnerability, and the malware can't infect those boxes
>independently.

It's not quite like that.
XP pre SP2 is vulnerable to attack. They will most likely
crash because of a wrong address, but they can be reached.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/