|
From: \ber GuidoZ <uberguidoz@gmail.com>
Date: Thu Sep 02 2004 - 14:33:53 EDT
I believe someone else mentioned this site on this list (not sure),
P.S. Send it to guidoz@guidoz.com - it's my "catch all" for
-- Peace. ~G On Thu, 2 Sep 2004 15:33:17 +0200 (CEST), bashis <mcw@wcd.se> wrote: > Hi > > Anyone heard about a file called "win2kup2date.exe" ? > (Google says nothing found..;) > > I did a controlled test with a XP Pro box w/o patches on Inet > and this little thingy came on my testbox thrue some sort of RPC exploit, > tftp'ed down this file from connecting machine, started with SYSTEM, > and tries to connect up to IRC. > > McAfee Virusscan Enterprise v8.0i with latest DAT's didn't find > any strange with this file.. > > That was actually my test, v8.0 of McAfee virusscan have a future of > "buffer overflow protection", it stopped the wellknown public RPC/DCOM > exploit, but not the exploit that putted "win2kup2date.exe" on my testbox. > > Well, so mutch for the new "buffer overflow protection" future.. crap.. ;) > > Have a nice day > /bashis _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.htmlReceived on Thu Sep 02 16:44:27 2004 This archive was generated by hypermail 2.1.8 : Thu Sep 02 2004 - 17:01:15 EDT |
Custom Search
|