Re: [Full-Disclosure] MS RPC remote exploit.

From: Stephen (alf1num3rik_at_yahoo.com)
Date: 10/09/03

  • Next message: Richard M. Smith: "[Full-Disclosure] Microsoft Outlines New Initiatives in Ongoing Security Efforts To Help Customers"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 9 Oct 2003 06:45:23 -0700 (PDT)
    
    

    --- Sudharsha Wijesinghe <sudharsha@digitalhouse.lk>
    wrote:
    > According to MS there cant be any Remote exploit on
    > MS RPC except for a
    > DOS attack using 139/135/445.
    > How ever the code is available for a shell code.
    > has any one tried this exploit?

    no remote exploit ?

    http://www.k-otik.com/exploits/10.09.rpc2universal.c.php
    http://www.k-otik.com/exploits/09.20.rpcdcom2ver1.1.c.php
    http://lists.netsys.com/pipermail/full-disclosure/2003-September/009848.html

    in MS03-039 we can see :

    ...There are three newly identified vulnerabilities in
    the part of RPCSS ...two that could allow arbitrary
    code execution and one that could result in a denial
    of service"

    Regards.

    __________________________________
    Do you Yahoo!?
    The New Yahoo! Shopping - with improved product search
    http://shopping.yahoo.com

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Richard M. Smith: "[Full-Disclosure] Microsoft Outlines New Initiatives in Ongoing Security Efforts To Help Customers"

    Relevant Pages

    • Re: [Full-Disclosure] MS RPC remote exploit.
      ... Sudharsha Wijesinghe wrote: ... > According to MS there cant be any Remote exploit on MS RPC except for ...
      (Full-Disclosure)
    • Re: my telnet cmd output problem solved
      ... > according to dump_log when remote cmd is executed, ... >> execution, in the $output, though the dump_log ... >> Do You Yahoo!? ...
      (perl.beginners)
    • [Full-Disclosure] MS RPC remote exploit.
      ... According to MS there cant be any Remote exploit on MS RPC except for a ... DOS attack using 139/135/445. ...
      (Full-Disclosure)
    • Re: Somebody tell Dave...
      ... got a remote with your TV?? ... I never read email at the Yahoo address! ... pencil on the fake microphone. ...
      (alt.fan.letterman)
    • Re: Somebody tell Dave...
      ... How many nitpicky little complaints can someone have ... before they do reach for the remote?!? ... I never read email at the Yahoo address! ...
      (alt.fan.letterman)