|
|
|
PivX provides Free Fix for the Microsoft® Internet Explorer Gopher Hole ![]() Newport Beach, California - June 13, 2002 (PRN): PivX Solutions, the creator of the patented and proprietary network intrusion security system Inviswall™ announced today that they have created a FREE Patch/FIX for the latest Microsoft® Internet Explorer™ security hole- Gopher Root Vulnerability[1]:(http://online.securityfocus.com/news/464) or (http://online.securityfocus.com/bid/4930/info/) "It would not take many minutes to put up a gopher server with a Win32'rootkit' as content, and then put an innocent but interesting looking link into a web page ('free live World Cup scores' would do nicely right now). And, with a link pointing to that server, have a page auto-forward to a malice gopher link, and, viola! A few more suckers rooted. This would likely pass through most firewalls as well." Simon Brooke, CTO Scaffie Ltd. Gopher was first discovered on May 22 by Online Solutions of Finland. (http://www.solutions.fi/) They did not release the exploit publicly, but instead sent the code directly to Microsoft so that hackers could not exploit it. They did the right thing by reporting the vulnerability directly to Microsoft rather than posting the exploit to the security community as some others have previously done. PivX just felt that getting a fix was important as well, so they created one. PivX found the syntax for the exploit and was able to custom craft a fix. It is just a matter of time until hackers find the general method on exploiting gopher to gain root access on a multitude of systems. There is always a catastrophic possibility for cyber terrorism or wide scale damage with any security hole or vulnerability, but with this one in particular. The simplicity of this attack coupled with the widespread usage of Internet Explorer™ would enable an amateur 'script kiddie' launch a full scale attack with less effort than sending a single mass e-mail. This could effectively turn millions of workstations around the world into an army of unstoppable drone soldiers, obliterating any target that they acquire within milliseconds. "Sure, this exploit only affects personal computers and small servers, but the power in all of the personal computers in the world clustered together is hundreds of thousands of times faster than any billion dollar government supercomputer. An even low-tech cracker that harnessed that would be unstoppable, and it is scary just how easy it would be to do so." Said Sam Balooch, Former Director Worldwide Datacenters SGI, PacBell, Sun, Wingcast Mobility. PivX initially released its first fix for this enormous hole on June 9th at midnight PST. After the first 15 hours we recorded over 75,000 downloads. Please visit the PivX Gopher-Smoker webpage for more information: http://www.pivx.com/gopher_smoker.html About PivX Solutions For more information please go to: http://www.pivx.com or you can email us at: press@pivx.com About Centrifuge Partners Centrifuge Partners can be reached at: centrifugepartners@earthlink.net ### Information from Press Release Network may be freely distributed to any publication. Wherever applicable, please cite Press Release Network as the news source. DISCLAIMER: The content of each press release is the responsibility of the publishing organization and is not vetted or approved by Press Release Network prior to publication. Press Release Network is not liable directly or indirectly for any direct or consequential loss, damage or expense resulting from the material disseminated and published on the site. Subscribers are advised to check the accuracy of all press releases and to obtain their own professional advice in relation to such information. 9219 |
|
[ HOME ]
[ ABOUT US ]
[ SERVICES ]
[ MEDIA ]
[ PRICING ]
[ ORDERS ] [ WHAT'S NEW? ] [ NEWSLETTER ] [ CONTACT US ] [ SITEMAP ] [ INDEX ] |
| PRN HAS OVER 20,000 MEDIA SUBSCRIBERS |