RE: MS03-049 Scanner?

From: Lela Armstrong (lela.armstrong_at_AES.com)
Date: 11/18/03

  • Next message: Sergey V. Gordeychik: "RE: Hiding MS SQL databases in Enterprise Manager"
    Date: Tue, 18 Nov 2003 15:59:20 -0500
    To: "Mason, Samuel" <smason@state.mt.us>, "Vidar Tyldum" <vidar@tyldum.com>
    
    

    Thor, Doesn't QwikFix do that?

     -----Original Message-----
    From: Mason, Samuel
    Sent: Tue Nov 18 15:53:52 2003
    To: 'Vidar Tyldum'; Mason, Samuel
    Cc: focus-ms@securityfocus.com
    Subject: RE: MS03-049 Scanner?

    Which requires admin privileges on the boxen... lovely. Couple this with the
    false reports for XP and we have a recipe for disaster.

    Samuel Mason
    Information Technology Security Office
    State of Montana
     

    -----Original Message-----
    From: Vidar Tyldum [mailto:vidar@tyldum.com]
    Sent: Tuesday, November 18, 2003 8:57 AM
    To: Mason, Samuel
    Cc: focus-ms@securityfocus.com
    Subject: Re: MS03-049 Scanner?

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Mason, Samuel wrote:

    > All,
    >
    > Is there a free tool available for identifying machines vulnerable to
    > MS03-049 on local networks yet or are we even expecting someone to develop
    > one?

    According to Nessus <http://nessus.org> this vulnerability can not be
    remotely checked without trying to trigger en vulnerability. Only
    'passive' way to check for it is to check the registry.

    More info: <http://cgi.nessus.org/plugins/dump.php3?id=11921>

    > Thanks!
    >
    > Samuel Mason
    > Information Technology Security Office
    > State of Montana

    - --
    Vidar Tyldum
    EOF
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1-nr1 (Windows XP)

    iD8DBQE/ukFYsJJnSzEQqpgRArbPAJ9cFlauQm2oMZcOisyhCxPdjQYOxQCeKr92
    Deqkne6C5VZwG+FDRfYifXs=
    =/Emx
    -----END PGP SIGNATURE-----

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------

    ________________________________________________________________________
    This email has been scanned for all viruses by the MessageLabs service.

    ________________________________________________________________________
    This email has been scanned for all viruses by the MessageLabs service.

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------


  • Next message: Sergey V. Gordeychik: "RE: Hiding MS SQL databases in Enterprise Manager"

    Relevant Pages

    • Re: CEH and Intense School
      ... > You want more than 4 to know the bugs are ironed out in labs and so on. ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • RE: strange ftp site
      ... Here are some quick prelim results of running strings against the exe file. ... A security error of unknown cause has been detected which has ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Incidents)
    • Re: Event Log messages for failed logon attempts
      ... >> Looking for a better way to manage your IP security? ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-Microsoft)
    • RE: Pen-testing remote VPN services over IP
      ... Institute for Security and Open Methodologies ... OPSA - OSSTMM Professional Security Analyst ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • Re: SOHO Hardware IDS
      ... What product are you currently evaluating?? ... >such as account numbers or social security numbers, ... >Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)