|
|||||||||||
|
RE: DCOM RPC exploit as a virus/trojan?
From: Dimitri Limanovski <dlimanov(at)sct.com>
Date: Fri Aug 01 2003 - 11:53:47 EDT Major issue is that not just 135/137/139 are exploitable. Any IIS box with COM Internet Services installed is exploitable over 80/443 (you'll have to modify exploit for that) and any machine that has RPC over HTTP is exploitable on 593 tcp/udp as well. As far as trojaned version, it is a matter of time, as someone said. Full Disclosure list already posted a working exploit that will try to exploit more that one host at a time. More to follow, I'm sure. Feds agree: <http://www.msnbc.com/news/946460.asp?cp1=1> Dimitri |---------+---------------------------->
| | "Benjamin D. | | | Goldman" | | | if you can dream it up, it can be done. If it can run on UDP - it can be done in such a way that will make it drearily impossible to stop.
-----Original Message-----
Just wondering, a newbie question really; theoretically, could the
Microsoft
The new MSN 8: advanced junk mail protection and 2 months FREE* http://join.msn.com/?page=features/junkmail --- Your network firewall and IDS products do not prevent Web application attacks - the most common form of online exploitation- resulting in Web defacement, data theft, sabotage and fraud. KaVaDo is the only company that provides a complete suite of Web application security products. Download a FREE whitepaper on "Security Policy Automation for Web Applications": http://www.securityfocus.com/Kavado-focus-ms ------------------------------------------------------------------------ --- --------------------------------------------------------------------------- Your network firewall and IDS products do not prevent Web application attacks - the most common form of online exploitation- resulting in Web defacement, data theft, sabotage and fraud. KaVaDo is the only company that provides a complete suite of Web application security products. Download a FREE whitepaper on "Security Policy Automation for Web Applications": http://www.securityfocus.com/Kavado-focus-ms --------------------------------------------------------------------------- --------------------------------------------------------------------------- Your network firewall and IDS products do not prevent Web application attacks - the most common form of online exploitation- resulting in Web defacement, data theft, sabotage and fraud. KaVaDo is the only company that provides a complete suite of Web application security products. Download a FREE whitepaper on "Security Policy Automation for Web Applications": http://www.securityfocus.com/Kavado-focus-ms ---------------------------------------------------------------------------Received on Fri Aug 1 11:56:36 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:34 EDT |
||||||||||
|
|||||||||||