hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

tribalgoa
1. windows messenger service (not msn) buffer overflow could lead to code execution !

http://xforce.iss.net/xforce/alerts/id/156

2. exchange 2000 smtp service buffer overflow could lead to code execution !

http://www.secunia.com/advisories/10015/

3. Windows May Allow Installation of Arbitrary ActiveX

http://www.secunia.com/advisories/10010/

4. Windows 2000 Buffer Overflow in Windows Troubleshooter
ActiveX Control

http://www.secunia.com/advisories/10011/

--------------------------------------------------------------------------------------------

These vulns are all extremely critical !!! We'll probably see a worm pretty soon for the 1st one ....

I can't believe that hole in windows messenger service wasn't found any sooner ... how simple can it get ??? maximum MESSAGE LENGTH is not checked ??? c'mon ... i can imagine the coders overlooked something here and there but not checking the MAIN input variable of your application is just plain dumb. (and weird it wasnt found sooner !?!?!)

If anybody sees rogue code for any of these I would like to know so I can force my manager to approve the bloody patches.
ducky
'eh thanks for the info mate...

i think a normal firewall could protect you very well against those thou...
or maybe i'm wrong
hermel
THX for the info smile.gif
boshcash
the most effective is the windows messenger service , since it can be done easily on all winnt systems , so patch and just wait for exploit and test it on other ppl
Yorn
You forgot the biggest one:

WinXP SP1 vulnerabilty to RPC Buffer Overflow(2).

From bugtraq:
**************************************************************
as confirmed by 3APA3A and security labs, it seems that the public exploit *works*
even if the patch MS03-039 is *installed*

This is a highly critical vulnerability - users MUST block vulnerable ports !

Regards.

K-OTik Staff /\\/ http://wwww.k-otik.com
**************************************************************

So yeah, the universal exploit for all windows versions of RPC(2) works even with a patched version of XP.
thatsmej
aaaaaah
those where meant here

*thatsmej slaps hisself*
boshcash
i am talking about those 4 vulnerabilities , rpc2 of course of one of 0days , and patch doesnt do the job , and vulns are accumulating day by day ..
0xc0000005
just check neworder 4 new bugs/exploits/overflows etc.

www.neworder.box.sk blink.gif
hermel
Nice site 0xc0000005 smile.gif
SoleKiller
well eather theyr real dumbassesor they wanted that hole to stay open so itll destract you from other holes they didnt figuer out how to close =D
d.K
a scanner was released for the first one

http://www.security.nnov.ru/search/exploits.asp

QUOTE

--- Copyright 2003 Internet Security Systems ---
Usage:
scanmsgr target=<range>
Scans systems on 135/udp testing for which are vulnerable to MS03-043
More help at: http://www.iss.net/support/product_utilities/ms03-043
Example: scanmsgr target=192.168.1.1-192.168.1.255

ComSec
QUOTE (d.K @ Oct 17 2003, 03:14 PM)
a scanner was released for the first one

http://www.security.nnov.ru/search/exploits.asp

QUOTE

--- Copyright 2003 Internet Security Systems ---
Usage:
scanmsgr target=<range>
Scans systems on 135/udp testing for which are vulnerable to MS03-043
More help at: http://www.iss.net/support/product_utilities/ms03-043
Example: scanmsgr target=192.168.1.1-192.168.1.255


its in the file downloads section wink.gif
tte
don't use it! it gives the vulnerable host a msg to fix the problem... doesn't help much if he then fixes it right? mad.gif
ComSec
what as in pop-up warnings....not tried it ?

if so hmmm ....i be reluctent to us it..could do you more harm !
0xc0000005
just check the source-code if it's a fake and secure all buggy server, it'll never worx
Gurou
Microsoft Windows Messenger Service Exploit (MS03-043)

http://www.k-otik.com/exploits/10.18.MS03-043.c.php

GaLiaRePt
Follow the discussion about this POC code at : http://forums.governmentsecurity.org/index...?showtopic=3519
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.