Exploit for Windows RPC may be in the wild!

From: Compton, Rich (RComptonat_private)
Date: Fri Jul 25 2003 - 12:45:35 PDT

  • Next message: Michael J. Pomraning: "email worm? Newsletter, aaa.exe, caraoke ksp.exe (fwd)"

    FYI, 
    ISPs are reporting a dramatic increase in traffic on TCP port 135.  No
    exploit code has been captured as of yet but the increase in traffic on this
    port probably indicates that exploit code is being executed!  Block ports
    135 through 139 and 445! 
    
    More info: 
    http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS
    03-026.asp
    
    -Rich Compton
    
    
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Sun Jul 27 2003 - 11:20:32 PDT