<<<
NEWS FROM THE LAB - Friday, December 5, 2008
>>>
 

 
Creating MS08-067 Exploits Posted by Mikko @ 11:10 GMT

We are seeing fair amounts of infections using the MS08-067 vulnerability.

Most of these belong to a worm family that goes by the names Downadup, Conficker, or Kido.

We have also discovered several Chinese tools that are being used by the underground to create files that exploit this vulnerability.

Below you'll see some screenshots of such tools.

ms08-067

ms08-067

ms08-067

ms08-067