Re: Alert: Microsoft Security Bulletin - MS03-039

From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 09/10/03

  • Next message: Russ: "Re: Alert: Microsoft Security Bulletin - MS03-039"
    Date:         Wed, 10 Sep 2003 15:06:40 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    I can't go into great detail at the moment, but suffice it to say that the vulnerabilities patched by MS03-039 represent new vectors for a Blaster-like worm to exploit, even if you have applied MS03-026.

    1. Disable DCOM

    or

    2. Patch now.

    I wouldn't be too worried about the RPC over HTTP or Tunneling TCP/IP vectors, its highly unlikely they would get used by any worm given how few systems have likely enabled them (neither are enabled by default.)

    Cheers,
    Russ - NTBugtraq Editor

    ----
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!
    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available.  And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to
    http://www.trusecure.com/offer/s0100/
    ----
    

  • Next message: Russ: "Re: Alert: Microsoft Security Bulletin - MS03-039"

    Relevant Pages

    • Re: Alert: Microsoft Security Bulletin - MS03-039
      ... The way that Microsoft patched the new RPC Part II vulnerability ... Summer's Hottest Certification Just Got HOTTER! ... To learn more about the TICSA certification, ...
      (NT-Bugtraq)
    • WHERE ARE NT4 OLD PASSWORDS STORED
      ... Sorry if this bores many of you (being an NT4 question), ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Firewalls and DCOM
      ... Never underestimate the lengths to which your users will inadvertently go through to infect a network;)" ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • DCOM worm analysis report: W32.Blaster.Worm
      ... A Bugtraq user has already pointed out that a worm has been ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Something changing DNS server settings
      ... When I looked in the registry of one of the affected computers, ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)