[Full-Disclosure] agobot and 1025

From: Willem Koenings (isec_at_europe.com)
Date: 04/29/04

  • Next message: insecure: "Re: [Full-Disclosure] Heads up: Possible lsass worm in the wild"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 29 Apr 2004 08:57:23 -0500
    
    

    hi all,

    in range of latest agobot's scans is port 1025. i know that
    by default there sits mstask and over rpc you can talk to
    him, add scheduled jobs etc (done this). sniffer captures
    reveals, that port 1025 attempts significantly resembles
    135 DCOM/blaster attempts.

    can anyone point out what and how _specifically_ are exploited
    in port 1025?

    W.

    -- 
    ___________________________________________________________
    Sign-up for Ads Free at Mail.com
    http://promo.mail.com/adsfreejump.htm
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: insecure: "Re: [Full-Disclosure] Heads up: Possible lsass worm in the wild"

    Relevant Pages

    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... Look in IIS at your Exchweb, Exadmin, exchange-oma, and RPC sites' directory ... Why is it called RPC over HTTP if HTTP is not really needed to be ... As pointed out by others, port 80 does NOT need to be open, and yes, it ... I have about 20 of these SBS machines at other locations and have ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... , but some of my clients do not want users to ... definitely closed now cause when I open it up http: ... the article is incorrect in stating that port 80 is needed. ... that port 443 and port 80 must be open to use RPC over HTTP. ...
      (microsoft.public.windows.server.sbs)
    • Re: Intersite Replication problem
      ... I followed Antony's DNS advise and I seens to be working. ... To perform the replication I've schedule a task on the W3K server to dial ... As for RPC The default value for the RPC Replication Timeout registry ... Remote Procedure Call dynamic port allocation is used by remote ...
      (microsoft.public.windows.server.active_directory)
    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... definitely closed now cause when I open it up http: ... the article is incorrect in stating that port 80 is needed. ... that port 443 and port 80 must be open to use RPC over HTTP. ... I have about 20 of these SBS machines at other locations and have ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 and Outlook RPC over HTTP issues
      ... Look in IIS at your Exchweb, Exadmin, exchange-oma, and RPC sites' directory ... manually...I just let the CEICW do it for me. ... Why is it called RPC over HTTP if HTTP is not really needed to be ... As pointed out by others, port 80 does NOT need to be open, and yes, it ...
      (microsoft.public.windows.server.sbs)