RE: MS05-039 Scanner

From: Marc Maiffret (mmaiffret_at_eeye.com)
Date: 08/17/05

  • Next message: khairul anwar mustapha: "RE: Microsoft Post Office on NT Server"
    Date: Tue, 16 Aug 2005 19:18:32 -0700
    To: <jeff@jeffbryner.com>, <michael_black@comcast.net>, <pen-test@securityfocus.com>
    
    

    A quick side note not to confuse MBSA or Shavlik with how Retina or
    others do it. Retina is able to detect the patch as missing, as Shavlik
    and MBSA do, (registry/file, which requires admin creds) but we also are
    able to remotely identify a vulnerable system without requiring
    authenticated credentials. That obviously makes it easier to find
    vulnerable systems on a Class B network because really who has
    credentials for a whole Class B and even if you miraculously did then
    what about all the systems you don't know about that are unmanaged and
    you definitely don't have access too. This is just one reason why stuff
    like MBSA is great for very small shops but is really unreasonable for
    any real network. Shavlik and others obviously are really meant more for
    patching, which means systems you know, so while it's a deficiency that
    they cant truly give you a view of vulnerability within your Class B
    network it's a limitation that is probably something they are not
    meaning to address in the first place, again because they do patch
    management instead of vulnerability management.

    Signed,
    Marc Maiffret
    Chief Hacking Officer
    eEye Digital Security
    T.949.349.9062
    F.949.349.9538
    http://eEye.com/Blink - End-Point Vulnerability Prevention
    http://eEye.com/Retina - Network Security Scanner
    http://eEye.com/Iris - Network Traffic Analyzer
    http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities

    Important Notice: This email is confidential, may be legally privileged,
    and is for the intended recipient only. Access, disclosure, copying,
    distribution, or reliance on any of it by anyone else is prohibited and
    may be a criminal offense. Please delete if obtained in error and email
    confirmation to the sender.
    -----Original Message-----
    From: Jeff Bryner [mailto:jbryner1@yahoo.com]
    Sent: Tuesday, August 16, 2005 9:29 AM
    To: michael_black@comcast.net; pen-test@securityfocus.com
    Subject: Re: MS05-039 Scanner

    > Does anyone know of any available scanners for this vulnerability? I
    > know Tenable has a plugin for Nessus and eEye has a free one for up

    I dunno if you've solved this or not, but the tenable ones are usually
    just templates that look for different hotfixes.

    The source for this particular one is on their website at:

    http://www.nessus.org/plugins/index.php?view=viewsrc&id=19402

    and you can see what it looks for.

    Assuming you have admin access to this class B network you could use the
    nessus plugin, or script something to mount the admin share and look for
    the hotfix.

    Alternatively http://hfnetchk.shavlik.com/ can also check for hotfixes
    remotely again assuming you have admin access.

    Jeff.

    ------------------------------------------------------------------------
    ------
    FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You
    Don't

    Learn the hacker's secrets that compromise wireless LANs. Secure your
    WLAN by understanding these threats, available hacking tools and proven
    countermeasures. Defend your WLAN against man-in-the-Middle attacks and
    session hijacking, denial-of-service, rogue access points, identity
    thefts and MAC spoofing. Request your complimentary white paper at:

    http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
    ------------------------------------------------------------------------
    -------

    ------------------------------------------------------------------------------
    FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't

    Learn the hacker's secrets that compromise wireless LANs. Secure your
    WLAN by understanding these threats, available hacking tools and proven
    countermeasures. Defend your WLAN against man-in-the-Middle attacks and
    session hijacking, denial-of-service, rogue access points, identity
    thefts and MAC spoofing. Request your complimentary white paper at:

    http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
    -------------------------------------------------------------------------------


  • Next message: khairul anwar mustapha: "RE: Microsoft Post Office on NT Server"

    Relevant Pages

    • [NT] CitectSCADA ODBC Service Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... are distributed in over 80 countries through a network of more than 500 ... A vulnerability was found in CitectSCADA that could allow a remote ...
      (Securiteam)
    • Re: Biometrics
      ... within a network for internal safety reasons and potentially to act as ... source code that is flexible enough to offer external security, ... Chris's distinction between the Internet and "a network" (presumably ... You quote a specific vulnerability below, about DNS, and you then make ...
      (microsoft.public.security)
    • RE: Pentesting vs VA - was Pentesting tool - Commercial
      ... How safe is it to outsource network management to an MSP, ... use site-to-site tunnels, SSL and SNMP V2? ... both vulnerability assessment and penetration testing. ... buy it or download a solution FREE today! ...
      (Pen-Test)
    • CERT Advisory CA-2002-12 Format String Vulnerability in ISC DHCPD
      ... The Internet Software Consortium provides a Dynamic Host ... have not seen active scanning or exploitation of this vulnerability. ... NSUPDATE allows the DHCP ... significant impact on your normal network operations. ...
      (Cert)
    • SecurityFocus Microsoft Newsletter #225
      ... Need to know what's happening on YOUR network? ... Netegrity SiteMinder HTML Page Injection Vulnerability ... Gallery Multiple Unspecified Input Validation Vulnerabilitie... ... Microsoft Internet Explorer Remote Information Disclosure Vu... ...
      (Focus-Microsoft)