Re: RPC DCOM exploit

From: morning_wood (se_cur_ityat_private)
Date: Mon Aug 04 2003 - 08:16:34 PDT

  • Next message: De Doncker, Steve: "RE: /tmp/pdk ?"

    >
    > Hmm...
    >
    > I haven't seen system log corruption, yet.  I'll have to keep my eye out
    > for that.
    >
    
    Neither have I
    
    >
    > In my latest tests, I've gotten failed processes on Windows 2000 SP2
    > boxen but Windows 2000 SP3/4 boxen have functioned properly after the
    > attack - with the attack only working once until a reboot occurs.
    >
    >        -Barry
    >
    >
    I still see mixed results in testing XP versions from 60 sec reboots no
    none, some reboot 60 secs after you exit shell, some dont.
    proally the best thing is to actually patch, firewall and mabey run a
    border IDS looking for the signatures I published.
    
    Donnie
    http://32-labs.com
    http://exploitlabs.com
    
    
    
    
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Mon Aug 04 2003 - 08:49:20 PDT