Starlight
hi all

i have this kind of results when I test lsass scans on port 139 whive check.exe

CODE

TMS       ,âxxx.xxx.xxx.xxx
TMS       ,âxxx.xxx.xxx.xxx
Windows 5.1 xxx.xxx.xxx.xxx
Windows 5.1 xxx.xxx.xxx.xxx
Windows 5.1 xxx.xxx.xxx.xxx
TMS       ,âxxx.xxx.xxx.xxx
TMS       ,âxxx.xxx.xxx.xxx
TMS       ,âxxx.xxx.xxx.xxx


is it normal?
are only the ips where the is "Windows 5.1" that are vulnerable.
is there a other checker for the lsass scans ?

thx a lot for your replys
LKM
I recommend you to use the official EEYE SASSER WORM VULNERABILITY scanner, which works VERY well in my case.

Here it is : Retina lsass.exe scanner
SHoCK
juste one question what's TMS ?!
EXPLOiTED
Well, Windows 5.1 and Windows 5.0 you will gain a shell. Also, TMS wiill gain u one also...and LKM you know your only gettign pcs Sasser hit..not teh full ranged plain lsass sploit
SHoCK
also u can use this scanner/checker, personaly i prefer this than eeye scanner ...


http://www.foundstone.com/resources/freeto...33f56104f524551
Starlight
thx all wink.gif
l0wkey
I hate how eeye is so anal about relasing a free scanner that scans more then one class c range. Makes people use other tools like the foundstone app.
bdark
the best one should be DSScan from Foundstone, but you won't get OS info on the scans results. But that's not a problem, cause you can check that with the exploit.

Here is a direct link: hxxp://www.foundstone.com/resources/freetools/dsscan.zip

hope it helps
6066up9r
DSScan gives the best results for me
toska
hey, this scan is way better...thanks for info!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.