[Full-Disclosure] locator exploit
From: Dave Aitel (dave@immunitysec.com)
Date: 02/01/03
- Previous message: Jonathan Rickman: "Re: [Full-Disclosure] The worm author finally revealed!"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Dave Aitel <dave@immunitysec.com> To: pen-test@securityfocus.com, full-disclosure@lists.netsys.com, bugtraq@securityfocus.com, vuln-dev@securityfocus.com, vulndiscuss@vulnwatch.org, NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM Date: Sat, 1 Feb 2003 01:57:06 -0500
So after writing the RPC locator exploit, I noticed that the service
is not actually vulnerable until it has been initialized
properly. Does anyone have any more information on how often and when
this service is intialized (as opposed to simply started)?
Here is tethereal output illustrating an uninitialized locator service:
192.168.1.101 -> 192.168.1.100 DCERPC Bind: call_id: 5 UUID:
e33c0cc4-0482-101a-bc0c-02608c6ba218 ver 1.0
192.168.1.100 -> 192.168.1.101 DCERPC Bind_ack: call_id: 5 Provider
rejection, reason: Abstract syntax not supported
In my testing environment this is the state of the locator service until
a local user binds to it to begin a lookup.
Other than this, the RPC Locator Service exploit is available as a
CANVAS module. (http://www.immunitysec.com/CANVAS/)
-dave
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Next message: Douglas F. Calvert: "Re: [Full-Disclosure] The worm author finally revealed!"
- Previous message: Jonathan Rickman: "Re: [Full-Disclosure] The worm author finally revealed!"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|