[Full-Disclosure] Latest MS Vulnerbilities

2004-02-11 Thread Jasper Blackwell
Hi All, MS have just released a new crop of serious vulnerabilities, MS04-004, MS04-006, MS04-007. I am assuming at the moment that there isn't any viruses, worms or exploit code in general circulation yet that exploit these holes. Although I imagine that people are working on it by now ;). Any

[Full-Disclosure] RE: RE: MSblast worm

2003-08-14 Thread Jasper Blackwell
Thanks for your answers all. TC's answer raises an interesting question for me. Does anyone know what exploit is being used as part of the MSBlast worm? I am aware that there are different versions of the DCOM32 exploit, some of these versions require you to determine what service pack is on th

[Full-Disclosure] MSblast worm

2003-08-14 Thread Jasper Blackwell
Hi All, Does anyone know if this MSblast worm affects Win NT machines, or is it just infecting 2000 and XP. Thanks Jasp _ Sign-up for a FREE BT Broadband connection today! http://www.msn.co.uk/specials/btbroadband __

[Full-Disclosure] MSBlast DDoS

2003-08-14 Thread Jasper Blackwell
Hi All, I should have kept on reading the list after TC's post and I would have found the answer to my question, doh :). It's early here and I hadn't had any caffine yet, always a bad idea trying to think before my morning caffine :). Anyway another question for you all. We are having some suc

Re: [Full-Disclosure] RPC DCOM Patches

2003-07-31 Thread Jasper Blackwell
Hi All, Are NT 4 Workstations vulnerable too, or just NT 4 Servers? NT 4.0 WS is bound to be vulnerable. MS did not release a patch because the product had hit its official end-of-life before the patch was released. ... Regards, Nick FitzGerald I have an NT4 workstation running SP6a which th

[Full-Disclosure] RE: DCOM Exploit MS03-026 attack vectors

2003-07-31 Thread Jasper Blackwell
Hi All, Microsoft owns up to the exploit being usable on 135, 139 and 445, I have heard rumors of port 80 being vulnerable as well. I was curious as to whether anyone had seen anything using a port other than 135? Everything I have seen discussed here and elsewhere has been 135 specific. Than