Exploit for Windows RPC may be in the wild!

From: Compton, Rich (RCompton_at_chartercom.com)
Date: 07/25/03

  • Next message: Michael J. Pomraning: "email worm? Newsletter, aaa.exe, caraoke ksp.exe (fwd)"
    To: incidents@securityfocus.com
    Date: Fri, 25 Jul 2003 14:45:35 -0500
    
    

    FYI,
    ISPs are reporting a dramatic increase in traffic on TCP port 135. No
    exploit code has been captured as of yet but the increase in traffic on this
    port probably indicates that exploit code is being executed! Block ports
    135 through 139 and 445!

    More info:
    http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS
    03-026.asp

    -Rich Compton

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Michael J. Pomraning: "email worm? Newsletter, aaa.exe, caraoke ksp.exe (fwd)"

    Relevant Pages

    • Fehlermeldung bei Forefront CS Installation mit Reporting Services
      ... Auf einem mir vorgegebenen Server muss ich ... Webdienst von SQL Server Reporting Services. ... QueryRosettaInformation: QueryRosettaInformation failed. ... das die Installation nicht mit dem Port 8080 klar kommt. ...
      (microsoft.public.de.sqlserver)
    • Re: (Where) should I report breakin attempts?
      ... Most of the time my computers are behind a router/firewall that blocks port ... I don't bother blocking / reporting Asian offenders. ... Don't use password authentication for public access, ...
      (comp.security.ssh)
    • Re: Drastic increase in "NetBIOS name" blocks
      ... >> ZoneAlarm has been reporting getting about 10x the normal amount of these over ... >> Port 1433 in the older versions of WinMX? ... as every script kiddie between here and Calcutta downloaded the tools to ... Lars M. Hansen ...
      (comp.security.firewalls)
    • Reporting fails on port 443
      ... Check the Reporting Point site system role and it has a ... of https protocol and a specific port number. ...
      (microsoft.public.sms.setup)
    • Re: Scanned for open relay ?
      ... >NIS reported port scans from 209.208.0.15 today. ... hundreds of reporting agents like myself, ... all I have to do is check my WW logs - and myNetWatchmen logs - ...
      (comp.security.firewalls)