|
|||||||||||
|
RE: Exploit for Windows RPC may be in the wild!
From: Jeff Adams <JAdams(at)NetCentrics.com>
Date: Tue Jul 29 2003 - 13:09:33 EDT
http://www.derkeiler.com/Mailing-Lists/VulnWatch/2003-07/0055.html I was successfully able to get it work on win2k, NT, and XP. I did not try 2k3. Both the win32 and unix versions can be found on the above newsgroup. It seems as though the success rate on un-patched machines is not 100% On un-patched machines I was getting it to work maybe 60 to 70% of the time. The exploit comes in a rpc port and then allows for cmd.exe netcat connection to port 4444. The code can be recompiled to drop the command line to a different port (say something common like 80)!! Jeff
-----Original Message-----
Does any one have working Exploit for "[NT] Buffer Overrun in RPC Interface Could Allow Code Execution" To be Specific Win NT 4.0
With Regard,
-----Original Message-----
tEA-TiME wrote Sunday, July 27, 2003 6:34 PM
Yes many could be messenger spam probes. I've seen a marked increase in TCP 135 scanning over the past week, though. And I'm getting new scan combos (TCP 135 and 445 with no other ports) that strongly suggest RPC probing rather than messenger spam. --- ------------------------------------------------------------------------ ---- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ ---- --------------------------------------------------------------------------- ----------------------------------------------------------------------------Received on Tue Jul 29 17:04:34 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:14 EDT |
||||||||||
|
|||||||||||