MS02-045 exploit is out

From: Kevin Gennuso (goosey@ICUBED.COM)
Date: 08/27/02


Date:         Tue, 27 Aug 2002 10:01:53 -0400
From: Kevin Gennuso <goosey@ICUBED.COM>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Hi all,

I haven't seen much noise on this list about MS02-045 (Unchecked Buffer in
Network Share Provider Can Lead to Denial of Service (Q326830)), but the
implications are very nasty. Any unpatched WinNT/2K/XP or .NET machine on
your network that's listening on port 139 and/or 445 can be crashed in
about two seconds with a malformed SMB packet. I highly disagreed with
Microsoft's assessment that this was only a "moderate" threat level to
intranet and desktop systems because the exploit is so easy to perform.

It was bad enough in theory, but now a script-tot friendly GUI version of
the exploit has been posted on PacketStorm, and it works against all of
the above. You can try for yourself at
http://packetstorm.decepticons.org/0208-exploits/SMBdie.zip

We worked through the weekend to get a large percentage of our boxen
patched - you may have to do the same.

The old "WinNuke" from the evil days of Win95 is back.

Thanks for listening,

Kevin



Relevant Pages

  • Re: Sometimes local network fileshares not detected
    ... At this time on my Vista machine (GoliathVista) there is nothing showing in the Network dialog, i.e., after I click on Network in the Start menu. ... operational WAN Miniport (L2TP) ... LISTENING 0xA ...
    (microsoft.public.windows.vista.networking_sharing)
  • Re: Maybe useful if you use a laptop for web dev...
    ... >>> I never could make DNS and Apache work if I had it setup to localhost. ... >>> machines on he network DNS queries failed. ... >> interfaces as they get addresses, and stop listening on interfaces as they ...
    (uk.comp.sys.mac)
  • @@@@@ i am a bit ambitious, so I stress you @@@@@
    ... people listening into private conversations, ... How can the FBI use computers to monitor thousands and thousands ... The Digital Telephony Act will allow them to legally - at full ... wiretapping capacity - dragnet-monitor the telephone network. ...
    (sci.crypt)
  • frontier today advocates Maggies destination
    ... people listening into private conversations, ... How can the FBI use computers to monitor thousands and thousands ... The Digital Telephony Act will allow them to legally - at full ... wiretapping capacity - dragnet-monitor the telephone network. ...
    (rec.crafts.brewing)
  • Re: printer
    ... box I started the printer setup procedure on the windows laptop. ... I need to do such as configuring CUPS to print from the network. ... You can also check if cupsd is listening by running 'netstat -l -t' in a ...
    (Ubuntu)