Original URL: http://www.channelregister.co.uk/2007/08/23/trend_micro_vuln_scanning/
Hackers have begun actively scanning for recently announced vulnerabilities in Trend Micro's ServerProtect product.
Security watchers at the Internet Storm Centre (ISC) have noted a huge upsurge of traffic on TCP port 5168, associated with security bugs (http://secunia.com/advisories/26523) in ServerProtect (an enterprise software product designed to protect servers and storage attacks).
Flaws in the application create a means for miscreants to load malware onto vulnerable systems. Fortunately, Trend Micro has published software updates designed to plug the security hole.
ServerProtect for Windows version 5.58 Build 1176 is known to be vulnerable, but other versions may also be flawed. Trend advises (http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch4_readme.txt) users to update to Build 1185.
Sys admins are advised to patch up vulnerable systems or run the risk of dealing with compromised machines. "It looks likes machines are getting owned with this vulnerability," ISC warned (http://isc.sans.org/diary.html?storyid=3306) on Wednesday.
More information on the vulns can be found in advisories from security tools vendor ISS, which discovered the majority of the vulnerabilities, here (http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=587) and here (http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=588). ®
Trend Micro buys leak prevention firm (25 October 2007)
http://www.channelregister.co.uk/2007/10/25/trend_acquires_provilla/
False positives run amok in Vista anti-virus tests (3 August 2007)
http://www.channelregister.co.uk/2007/08/03/64bitvista_av_tests/
The decline of antivirus and the rise of whitelisting (27 June 2007)
http://www.channelregister.co.uk/2007/06/27/whitelisting_v_antivirus/
Trend Micro boosts Vista package, extends Hotmail deal (26 June 2007)
http://www.channelregister.co.uk/2007/06/26/trend_loves_redmond/
Trend Micro overhauls EMEA channel programme (26 April 2007)
http://www.channelregister.co.uk/2007/04/26/trend_micro_emea_channel/
Trend Micro to kick butt on botnets (26 September 2006)
http://www.channelregister.co.uk/2006/09/26/trend_micro_botnet_appliance/
Trend Micro archive bug unearthed (25 February 2005)
http://www.theregister.co.uk/2005/02/25/trend_micro_vuln/
Trend Micro squashes buffer overflow bug (12 December 2002)
http://www.theregister.co.uk/2002/12/12/trend_micro_squashes_buffer_overflow/
© Copyright 2008