<<<
NEWS FROM THE LAB - Tuesday, March 27, 2012
>>>
 

 
A Tool Exploiting MS12-020 Vulnerabilities Posted by ThreatSolutions @ 06:48 GMT

Since the public release of Microsoft's MS12-020 bulletin, there have been plenty of attempts to exploit vulnerabilities in the Remote Desktop Protocol (RDP). Last week, we received a related sample, which turned out to be a tool called "RDPKill by: Mark DePalma" that was designed to kill targeted RDP service.

RDPKill

The tool was written with Visual Basic 6.0, and has a simple user interface. We tested it on machines running on Windows XP 32-bit and Windows 7 64-bit.

RDPKill

Both the Windows XP 32-bit and the Windows 7 64-bit computers were affected by the Denial of Service (DoS) attack. The service crashed and triggered a "Blue Screen of Death" (BSoD) condition (the error screen seen when Windows crashes).

RDPKill BSoD

We detect this tool as Hack-Tool:W32/RDPKill.A. (SHA-1: 1d131a5f17d86c712988a2d146dc73367f5e5917).

Besides RDPKill.A, other similar tools and Metasploit module can also be found online. Due to their availability, an unpatched RDP server would be an easy target of DoS attack by attackers who might be experimenting with these tools.

For those who still haven't patched their system, especially those running RDP service on their machines, we strongly advise that you to do so as soon as possible.

—————

Threat Solutions post by — Azlan and Yeh