<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; microsoft windows</title>
	<atom:link href="http://www.darknet.org.uk/tag/microsoft-windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hackers Exploiting Unpatched DirectX Bug With Quicktime</title>
		<link>http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/</link>
		<comments>http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 10:41:21 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[directx exploit]]></category>
		<category><![CDATA[directx vulnerability]]></category>
		<category><![CDATA[hacking directshow]]></category>
		<category><![CDATA[hacking directx]]></category>
		<category><![CDATA[hacking microsoft]]></category>
		<category><![CDATA[hacking quicktime]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft windows]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1826</guid>
		<description><![CDATA[It seems like another fairly critical flaw has been discovered in Microsoft Windows. It&#8217;s serious as it allows remote code execution, which basically means if you get hit with it your machine is owned. It seems DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk. Windows Vista, Server 2008 [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems like another fairly critical flaw has been discovered in <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> Windows. It&#8217;s serious as it allows remote code execution, which basically means if you get hit with it your machine is owned.</p>
<p>It seems DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk. Windows Vista, Server 2008 and Windows 7 are not effected &#8211; so they have fixed the problem at some point in their development cycle, they just haven&#8217;t pushed it back to the older operating systems yet.</p>
<blockquote><p>For the third time in the last 90 days, Microsoft Corp. has warned that hackers are exploiting an unpatched critical vulnerability in its software.</p>
<p>Late Thursday, Microsoft issued a security advisory that said malicious hackers were already using attack code that leveraged a bug in DirectX, a Windows subsystem crucial to games and used when streaming video from Web sites.</p>
<p>Hackers are using malicious QuickTime files &#8212; QuickTime is rival Apple Inc.&#8217;s default video format &#8212; to hijack PCs, Microsoft said. &#8220;The vulnerability could allow remote code execution if [the] user opened a specially crafted QuickTime media file,&#8221; the company said in the advisory. &#8220;Microsoft is aware of limited, active attacks that use this exploit code.&#8221;</p>
<p>According to Christopher Budd, a spokesman for the Microsoft Security Response Center, QuickTime itself is not flawed. Instead, the QuickTime parser in DirectShow, a component of DirectX, contains the bug. &#8220;An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in e-mail,,&#8221; Budd said in an entry on the MSRC blog.</p></blockquote>
<p>Microsoft has had quite a spate of serious vulnerabilities recently, it seems resourceful hackers are targeting applications and components of the OS rather than the actual OS or networking stack.</p>
<p>Which makes sense, you&#8217;d expect the actual OS to be fairly secure now and not attention has been paid to those &#8216;must-have&#8217; system softwares like DirectX.</p>
<blockquote><p>Because the bug is in DirectShow, any browser using a plug-in that relies on DirectShow is also vulnerable.</p>
<p>DirectX 7, 8 and 9 in Windows 2000, XP and Server 2003 are at risk, Budd said, but Vista, Server 2008 and Windows 7 are not. &#8220;Our investigation has shown that the vulnerable code was removed as part of our work building Windows Vista,&#8221; Budd said.</p>
<p>Until a patch is available, users can protect their PCs by disabling QuickTime parsing. To do that requires editing the Windows registry, normally a task most users shy from, but Microsoft has automated the workaround. &#8220;We&#8217;ve gone ahead and built a &#8216;Fix it&#8217; that implements the &#8216;Disable the parsing of QuickTime content in quartz.dll&#8217; registry change,&#8221; Budd said. &#8220;We have also built a &#8216;Fix it&#8217; that will undo the workaround automatically.&#8221; </p></blockquote>
<p>Watch out when you are opening video files from unknown sources, especially in e-mail attachments (even from known sources) and you can use the &#8216;Fix it&#8217; to mitigate against the problem until the patch is released.</p>
<p><a href="http://support.microsoft.com/kb/971778">Microsoft Security Advisory: Vulnerability in Microsoft DirectShow could allow remote code execution</a></p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/052909-hackers-exploit-unpatched-windows.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1826+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;t=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/&amp;title=Hackers+Exploiting+Unpatched+DirectX+Bug+With+Quicktime" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fhackers-exploiting-unpatched-directx-bug-with-quicktime%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/hackers-exploiting-unpatched-directx-bug-with-quicktime/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

