saetji
Nov 13 2003, 06:45 PM
how do u check if a system is patched against the blaster exploit?
ssj4conejo
Nov 14 2003, 03:47 AM
blaster is not an exploit. it is the worm that took advantage of the old rpc exploit. Locally you can probably check with the first dcom(rpc) exploit, quite easily either with scanners or by trying to run the exploit itself, which still probably lays around this forum. you can also try rpc2 and the new messenger exploit as well. Also doing it remotely is a little more tidious because most isp's have blocked the rpc and netbios ports. so you have to find isp's that don't block it which is a matter of luck.
ICEBUGZ
Dec 8 2003, 04:28 PM
Saetji,
I had a lot of luck using Retina's free scanner at
http://www.eeye.com/html/Research/Tools/Do...e=RetinaRPCDCOMHope that helps...........
ICEBUGZ
hidden
Dec 8 2003, 06:11 PM
thx for the scanner
coder
Dec 8 2003, 06:18 PM
saetji: Use the Windows Update Utility (%SystemRoot%\system32\wupdmgr.exe) to search for the latest patches (if you have access... if not, there are many scanners for the RPC exploits...)
Helloman
Dec 12 2003, 10:26 AM
I think RPC is more than dead because evry stupid admin should know about that hole and a lot of isp providers block that port .
nulladd
Dec 12 2003, 02:03 PM
that is true, but then again rpc3 was quite fun against someone during a lan day (you know who you are)
The-X
Dec 14 2003, 10:40 AM
you wont find any good servers running with unpatched windows...
| QUOTE |
| I think RPC is more than dead because evry stupid admin should know about that hole and a lot of isp providers block that port . |
yeah ya right...
SkyRaVeR
Dec 14 2003, 10:57 PM
for sure... more then dead! try focussing on other xploits
taimoor
Dec 29 2003, 12:48 PM

buty
Axl
Dec 30 2003, 09:24 AM
I wanna kill the (filtered) who designed blaster... bastard (filtered) it up for everyone.
saetji
Jan 3 2004, 08:57 PM
heh true quantum. I know I wont find any - but im just curious

I try to understand the stuff rather than just use it

and knowing proggys to help that is always good
beenal
Jan 4 2004, 02:55 AM
the best way to check if a system is patched against the blaster is in my opinion: plug in the network cable
after reinstalltion of win2k, i plugged in my network card, and after 5 seconds, i got the worm :/ didn't have any time to patch my machine against it, this worm is really hardcore
thotho
Jan 5 2004, 06:37 AM

use afirewall
xzibit
Jan 7 2004, 03:11 AM
no no. the rpc/dcom exploit is far from dead. Still many vulnerable hosts. Also, everytime a fresh new install of Windows XP hits the internet. It is vulnerable
akis
Jan 7 2004, 02:57 PM
well the best way(for me)to check it and ofcourse disable it without ms patch is grc.com methoD!goto
http://grc.com/dcom/ and try this.They also have cool programs like disable the messenger and that stuff.Give them a try and you will not lose!
The Storm
Jan 9 2004, 02:30 PM
i don`t agree if you say every new system is vulnerable. Truly it is but most server admins i know first install all patches from MS and then connect to the internet. But eventually you`re lucky and find a gut vulnerable server!
xzibit
Jan 9 2004, 04:47 PM
| QUOTE (The Storm @ Jan 9 2004, 02:30 PM) |
| i don`t agree if you say every new system is vulnerable. Truly it is but most server admins i know first install all patches from MS and then connect to the internet. But eventually you`re lucky and find a gut vulnerable server! |
u do have a point but the average home user may not think of that
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.