[Full-Disclosure] Odd Behavior - Windows Messenger Service

From: morning_wood (se_cur_ityat_private)
Date: Wed Jul 16 2003 - 02:36:40 PDT

  • Next message: Ken Pfeil: "Re: [Full-Disclosure] Odd Behavior - Windows Messenger Service"

    Donnie Werner
    morning_woodat_private
    July 16, 2003
    
    Windows® networking ( TCP) and messenger service are both initialized
    before any user/admin login
    has taken place, and are remotely accessable
    
    
    odd... setting up default XP box in DMZ  I complete the install setting up
    networking ( dhcp ) and ( workgroup )
    only one passworded administrator account as prompted by the instalation
    media.... reboot.
     I leave box unatended for aprox 30 minuts at the login screen...
    Upon sucessfull passworded login, a message-ala-windows messenger service
    is displayed.. ( damn spammers )
    
    BEFORE THE DESKTOP !!! and before anything ( except wallpaper ) has
    initialized
    
    
    here is output from a remote nbtenum session before a sucessfull login of a
    freshly booted XP box
    
    Network Adapter Adapter: \Device\NetbiosSmb
    MAC Address: 000000000000
    Adapter: \Device\NetBT_Tcpip_{D36A0C7D-1EC4-417E-9A7C-DF4F13AF9D4C}
    MAC Address: 00A0CC397071
    Logged On Users Username: 333\BITCHBOX$
    Logon Server:
    Share Information IPC$
    ADMIN$
    C$
    
    dunno if this particular behavior has been observed before ( im donning
    Nomex® for the flames )
    
    Donnie Werner
    http://exlpoitlabs.com
    
    
    
    
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Wed Jul 16 2003 - 03:09:45 PDT