Symantec is reporting an active exploit site for the QuickTime RTSP Response vulnerability described in CVE-2007-6166. Currently, the malicious stream is hosted at port 554 on the server 85.255.117.212. Upon exploitation, the following executables are downloaded:
hxxp:// 1800-search.com /000/loader.exe
hxxp:// 1800-search.com /000/dnslvc.exe
Both files are universally detected by anti virus, so this is a relatively badly executed attack. Since no vendor supplied patch is currently available, we still recommend following US-CERT's recommendations:
Each of these does make the use of valid Quicktime content next to impossible, so please be aware of the impact this may have on your organization.
This specific attack instance can be blocked by disallowing traffic to the following domains and IP addresses:
2005-search.com
1800-search.com
85.255.117.212
85.255.117.213
216.255.183.59 (a seeder URL to this exploit, also hosting other IE exploits)
--
Maarten Van Horenbeeck
Login here to post a comment. Diary Archive