[Full-Disclosure] MS RPC remote exploit.

From: Sudharsha Wijesinghe (sudharsha_at_digitalhouse.lk)
Date: 10/09/03

  • Next message: Brendan Gregg: "[Full-Disclosure] Chaosreader: Trace TCP/UDP from snoop/tcpdump logs"
    To: full-disclosure@lists.netsys.com
    Date: 09 Oct 2003 18:41:49 +0600
    
    

    According to MS there cant be any Remote exploit on MS RPC except for a
    DOS attack using 139/135/445.
    How ever the code is available for a shell code.
    has any one tried this exploit?

    Sudharsha

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Brendan Gregg: "[Full-Disclosure] Chaosreader: Trace TCP/UDP from snoop/tcpdump logs"

    Relevant Pages

    • Re: [Full-Disclosure] MS RPC remote exploit.
      ... Sudharsha Wijesinghe wrote: ... > According to MS there cant be any Remote exploit on MS RPC except for ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] MS RPC remote exploit.
      ... > According to MS there cant be any Remote exploit on ... > MS RPC except for a ... Do you Yahoo!? ...
      (Full-Disclosure)
    • temporary fix for Windows rebooting with RPC message
      ... A possible temporary fix for the rebooting Windows machine with the RPC ... Remote Access Auto Connection Manager ... First select the Remote Access Connection Manager with the secondary ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Exchange 2003 with 3 locations...
      ... I have not studied the rpc over http bandwidth consumption before. ... >> 200 users is a lot for the full client on a T1 even with cached mode. ... >> Might want to look into mailbox servers at the remote sites... ... >> Windows Server MVP ...
      (microsoft.public.exchange2000.general)
    • Re: Remote procedure call
      ... run the "Remote Procedure Call" service despite the fact that I don't allow anybody access to my computer via remote help? ... John, thanks for replying. ... Yes, I'm aware that RPC handles calls between processes and services, but it seems to me that inner-computer calls could be handled discretely from inter-computer calls. ... NT systems are client/server systems, a process that makes a request to another process is a client and the process that responds to the request is a server, the the interprocess communication can be local or across a network, they're all client/server transactions. ...
      (microsoft.public.windowsxp.general)

    Loading