hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Pages: 1, 2
Nexcess
hxxp://www.securityfocus.com/news/8003

What are they on about? It sounds really big.
-Nexy


Maybe its one of these...

hxxp://eeye.com/html/Research/Advisories/AD20040210.html

hxxp://eeye.com/html/Research/Advisories/AD20040210-2.html
Erra
I would say its both of those ones you mention....

Problem is, it runs on Port 135,139 and 445.

These ports have been blocked by a lot of ISP's since blaster, messenger, workstation, which all used this port. Thats why workstation and messenger werent great exploits imho
Divx_dude
some isp's dont block it like mine so it come in handy when exploit will be releasd good job for the post !
wlingard
OMG .. looks like Microshit are in for some more hardcore worm action!

That's a serious couple of vunerabilities.. deffo something to watch!

Thanks for posting! biggrin.gif

//WL
PrarieDog
yup these new ones will definately make splash in micro$hit.
blazeking
how long before a brave virus author releases one to exploit these? a week? two? place your bets now!


and this is not just an attempt to get to 50... some part of me actually enjoys hearing about a security hole, then patching my own system, and watching the rest of the world suffer because they are too stupid or too lazy to keep up with the crap M$ spews out.

then again at work i'm going to have a hell of a time informing people how to stay up to date... didn't we do this with blaster? wtf? stupid users, if it wasn't for job security, i'd get rid of them.
elfeo
couldnt be that tonight?? smile.gif
Gotisch
9 days from now for a public release !
elfeo
thats a bet, or u know that for sure?
dillusionalchaos
He wouldn't be posting it publicly if he knew,cause if it was released the feds would come after him first. wink.gif
dstevens1958
lol, well while all u ppl were betting on a release date, I was finishing up the removal of some bastard worm that got in my machine. (My mistake, I freshly formatted, wasn't aware of a nasty exploit, didn't have AV installed yet, and paid dearly for it) I'm not sure if this worm was actually the exploit, could just be coincidence that I got infected while a crazy exploit was flying around everywhere. Thankfully my firewalls caught most of the outbound traffic that this thing was trying to send out, (mostly attacking port 135), but I'm sure some got through.

Why am I telling u this? Well, first so you can laugh at me. Second, just a reminder that after you format, install AV before downloading files! lol. I was just being lazy, thinkin, 'ah, haven't got a virus for 3 months, I'll be OK!" well, that blew up in my face and spent a couple hours trying to kill the stupid thing and gather up my firewall logs in case my ISP gets angry with me. It hit pretty good, my ISP actually dropped offline for a while, and connections were flaky at best, however web suring was completely impossible, as was using MSN. (Well, at least I could ping google, just couldn't search for anything other than... packets? lol)

See what happens when I use windowz? I get attacked, use Linux, and I get productive! <<sigh>> it will never end....

Take care!

Dave
Major Chrome
Actually, I think he was just trying to make 50 posts.
nubela
lol.. wad xploit is it?
tba
yes please be specific
ComSec
btw....

Vendor Status:

Microsoft has released a patch for these vulnerabilities. The patch is available at:

http://www.microsoft.com/technet/security/...in/MS04-007.asp

Nexcess
The tech. details are always interesting between 007, 006 thats about every pc made in the past couple years. tongue.gif

*smile*
ipc$hacker
QUOTE (Major Chrome @ Feb 11 2004, 01:54 AM)
Actually, I think he was just trying to make 50 posts.

and why u follow him?
h3llraz0r
looks like a really nasty screw up by microsoft again dry.gif
DJohn84
And the countdown begins to where someone will attach a worm to this sad.gif

Ah well, bring on the source code smile.gif
n4than_69
> -----Original Message-----
> From: Marc Maiffret [mailto:mmaiffret@eeye.com]
> Sent: Tuesday, February 10, 2004 10:20 AM
> To: BUGTRAQ@securityfocus.com
> Subject: EEYE: Microsoft ASN.1 Library Length
> Overflow Heap Corruption

> Microsoft ASN.1 Library Length Overflow Heap
> Corruption
>
> Release Date:
> February 10, 2004
>
> Date Reported:
> July 25, 2003
>
> Severity:
> High (Remote Code Execution)
>
> Systems Affected:
> Microsoft Windows NT 4.0 (all versions)
> Microsoft Windows 2000 (SP3 and earlier)
> Microsoft Windows XP (all versions)
>
> Software Affected:
> Microsoft Internet Explorer
> Microsoft Outlook
> Microsoft Outlook Express
> Third-party applications that use certificates
>
> Services Affected:
> Kerberos (UDP/88)
> Microsoft IIS using SSL
> NTLMv2 authentication (TCP/135, 139, 445)

http://www.eeye.com/html/Research/Advisories/AD20040210.html
http://www.eeye.com/html/Research/Advisori...20040210-2.html
tba
Dude we know that now how to get the patches do you have any code for this thang biggrin.gif
Cyphie
I'm sure when someone has developed exploit code for this vulnerability it will be kept private for a while. ph34r.gif
tba
well there has anyone found the code for this "leak"?
Cow|
Ahhh who said that 2004 wouldn't be a good year tongue.gif
Vosgia
i heared about it early in the morning, in every radio smile.gif
so i think all administartors will patch their systems soon.
QuadMedic
huh.gif oh this could be a nice one........... Thanx for MicroSnot ........ we have to patch our servers daylly..... mad.gif
DMX2
Nice nice....

Hope to see a real working exploit soon...


Greetzzz to all
Yorn
This exploit is not limited to blocked ports. In fact, in some instances the ISPs CANNOT block them. Like Kerberos. If they blocked that, universities nationwide would throw their hands in the air in disgust.

Any bets on what new vulnerabilities this patch is going to open?
shiz
QUOTE

Any bets on what new vulnerabilities this patch is going to open?


lol..

but seriously, this is all over the news here where i live...
we immediately saw scanning activities increase at our school's network..
:S
tba
why scanning if there is no compiled version???
Thom
Good question
Raedemer
Can't wait to see the exploit code, but I think lot's of isp secured the ports wich this bug is using. Publish the code, and I think lot's of ppl will update their pc tongue.gif
spooky
hm
I think this bug(ASN.1 Library ) is known since 6 month to microsoft.

But the code of the leak isn't public yet(i think).

If someone founds the code, I think no1 will make it public cause this would we be deadly for all windows users ^^
(hmm but sounds funny)
Divx_dude
lol if it comes publics tongue.gif evryone that didnt patched there systems will be a stro or somthing else unsure.gif
Copkill
I hope he comes before all system´s are patched rolleyes.gif
nolimit
2 reasons for scanning I can think of right off the top of my head,
#1: Preparation for public POC releasal
#2: Not everyone waits for a POC, Some are able to recreate the overflow on there own.
xzibit
QUOTE (tba @ Feb 11 2004, 03:30 PM)
why scanning if there is no compiled version???

just because u dont see it, doesnt mean its not there cool.gif
hitu
Microsoft has been releasing patches for it frequently.. seems somethin big tongue.gif
Erra
QUOTE (xzibit @ Feb 11 2004, 08:54 PM)

just because u dont see it, doesnt mean its not there cool.gif

how very true........ exploits are very often private first....

eEye discovered it, so they will have the exploit code somewhere...

Lusty
Yeah.. would be very nice with that kind of exploid.. Hope it come soon
Max_Payne
seems that everyone freaked out already.. biggrin.gif

QUOTE

ERROR
The requested URL could not be retrieved

--------------------------------------------------------------------------------

While trying to retrieve the URL: http://www.microsoft.com/technet/security/...in/MS04-007.asp

The following error was encountered:

Connection Failed
The system returned:

    (60) Operation timed out


ahaha biggrin.gif
Paul
Most of the "usefull" exploit are private first, when its almost "dead" it'll be released public.
Though, you only need one pc to get in, and lanhack the other ones.
Cause some isp's blocked it, doesnt mean u cant hack them anymore.
Microsoft released the patch lately, if this been out for 6 months wink.gif .
Major Chrome
QUOTE (ipc$hacker @ Feb 11 2004, 05:34 AM)
QUOTE (Major Chrome @ Feb 11 2004, 01:54 AM)
Actually, I think he was just trying to make 50 posts.

and why u follow him?

It seems to me that your doing the exact same thing, I was just pointing out why he was doing that. Clear my post count for this post for all I care.

As for the virus, I'll install the patch, Thanks Com!
Fooldj
i read that microsoft HAS known about this problem for 6 months, but their just now releasing a patch, and even tho some isp's bock those ports, some dont, and those comps will be vulnerable, which makes the sploit good, i know my isp dosen't block the 139, 445, and shit until you abuse them, and other isp's dont even care as long as you aren't scanning on those ports. personally i think if someone can get this sploit it will be very usefull for a while, there are alot of stupid/lazy people that just dont care. i mean, i can still get tons of results with regular NT sploit....
Nexcess
QUOTE (Fooldj @ Feb 13 2004, 02:41 AM)
i mean, i can still get tons of results with regular NT sploit....

Nah most of the regular universities block those ports now, so figure that it will be useless to most of us before it even comes out. Mydoom is dead, nothing fast left with it that isnt already comprimised. We need a real exploit like rpc again on a port that isn't blocked. Maybe 3389 remote desktop or upnp.. something nice smile.gif
Hopefully, these worm/virus writers will bugger off and let us enjoy the next exploit the media gets ahold of the fact theres a new worm/virus and every sysadmin and his sheep run to microsoft for a patch sad.gif
Axl
QUOTE (Nexcess @ Feb 13 2004, 03:15 AM)
QUOTE (Fooldj @ Feb 13 2004, 02:41 AM)
i mean, i can still get tons of results with regular NT sploit....

Nah most of the regular universities block those ports now, so figure that it will be useless to most of us before it even comes out. Mydoom is dead, nothing fast left with it that isnt already comprimised. We need a real exploit like rpc again on a port that isn't blocked. Maybe 3389 remote desktop or upnp.. something nice smile.gif
Hopefully, these worm/virus writers will bugger off and let us enjoy the next exploit the media gets ahold of the fact theres a new worm/virus and every sysadmin and his sheep run to microsoft for a patch sad.gif

Hmm... I know several 100mbit + ranges that do not block those ranges. Also, do not forget, this affects IIS ssl mmm. When this comes out, I will be ecstatic.
GhostCow
blah microsoft are so poorly foolish... i just heared that some windows source codes were leaked... its because of all the companies that work with them that need the source to be able to develope software for winblowz...
technoboy
QUOTE
i just heared that some windows source codes were leaked...


Yes, from now available on your closest warez server smile.gif

Prepare for even more MS vuln's this year !
Axl
QUOTE (GhostCow @ Feb 13 2004, 01:51 PM)
blah microsoft are so poorly foolish... i just heared that some windows source codes were leaked... its because of all the companies that work with them that need the source to be able to develope software for winblowz...

Nah, they mostly give it to the colleges in texas and stuff and just the sdk to the software developers. Methinks a killer version of cygwin will be out though... = total compatibility for the windows environment in linux applications and vice versa. Mmmm... nice driver development for linux too.
JaX
seems like a good sploit smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.