RealNetworks RealServer G2 buffer overflow - WORKAROUND (fwd)

From: ah1at_private
Date: Thu Nov 04 1999 - 14:28:46 PST

  • Next message: Thomas Biege: "Re: hylafax-4.0.2 local exploit"

    ---------- Forwarded message ----------
    Date: Thu, 4 Nov 1999 15:08:08 -0700
    From: Mark <markat_private>
    Reply-To: Discussions regarding Windows-related security issues.
        <WIN2KSECADVICEat_private>
    To: WIN2KSECADVICEat_private
    Subject: RealNetworks RealServer G2 buffer overflow - WORKAROUND
    
    A Web site reader at www.ntsecurity.net, Brendan Brannen, sent me this
    message with a workaround to help any of you that are using the RealServer
    G2:
    
    ===============
    
    "While this may not be the best fix for everyone, on our server, I simply
    went in to the .cfg file and (after backing it up of course) deleted the
    entry that specified the admin port. I then stopped and restarted the
    rmserver service. While this does of course effectively turn off the
    administrative capabilities of the software, you can of course switch
    between your backed up version and the new one of the CFG file to re-enable
    this service.
    
    It's a kludge, but it fixes the hole until Real comes out with something..."
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:09:44 PDT