Thanks,
Al
At 03:32 PM 9/10/2003 -0700, you wrote:
Funny, as I work with Eeye alot and I did not hear that techsanctuary had anything to do with the discovery according to Microsoft. Congrats on your discovery!
There is a new Microsoft scanning tool to replace the old one that actually scans for both patches at the same time and is lighting fast. Hopefully your everyone's patch management solution is in place. We use SUS server (a free product of course) and have already patched 3000+ machines in our Enterprise with this application.
If anyone else uses SUS, email me offline. Curious to see your results!
Regards,
Mark Schaefer Sr. Technical Analyst Edwards Lifesciences LLC 949 250 3557 Phone 949-809-7354 FAX 949-203-9050 Pager [EMAIL PROTECTED]
"William Lefkovics"
<[EMAIL PROTECTED] To: <[EMAIL PROTECTED]>
rg> cc:
Sent by: Subject: Re: [IMail Forum] OT: Another Rpc Exploit
[EMAIL PROTECTED]
pswitch.com
09/10/2003 03:01 PM
Please respond to
IMail_Forum
Ya... we sent it to Microsoft in May. :o)
The way that Microsoft patched the new RPC Part II vulnerability actually breaks most scanning tools looking for the first flaw. That is to say that if your company is using a scanning tool looking for MS03-026 and you have installed MS03-039 then your MS03-039 systems will be flagged as vulnerable, when they obviously are not.
Since we actually found the flaw we were able to update Retina and our free scanning tool to correctly identify this new vulnerability, and old, without getting false positives. Again, last time I checked ISS, Foundstone, and a couple free tools (MS's old version), will incorrectly identify systems as vulnerable to the old flaw, with this new patch installed.
Retina 4.9.126 and our free RPC scanner Version 1.1.0 have the correct checks that the rest of the scanners are going to need to "model themselves" after in order to accurately detect these RPC flaws. Again the free RPC scanner tool, with latest RPC check, can be downloaded from:
http://www.eeye.com/html/Research/Tools/RPCDCOM.html
William Lefkovics eEye Digital Security
----- Original Message ----- From: "Dave Marchette" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, September 10, 2003 2:49 PM Subject: [IMail Forum] OT: Another Rpc Exploit
http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-039.asp
Apologies if this has been sent already.
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
