Re: [Full-Disclosure] RE: DCOM Exploit MS03-026 attack vectors

2003-08-02 Thread Geoincidents
heh... http://www.nthelp.com/dcom.htm ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

RE: [Full-Disclosure] RE: DCOM Exploit MS03-026 attack vectors

2003-08-01 Thread Parker, Jeff (MSE)
Please do not forget port 593/tcp and 593/udp. If you (or someone else) heard something about the vulnerability working over http (rumored to 80/tcp), port 593 is what you should be aware of. The DCOM vuln is indeed usable over port 593. -Original Message- From: Jasper Blackwell [mailt

Re: [Full-Disclosure] RE: DCOM Exploit MS03-026 attack vectors

2003-08-01 Thread Richard Spiers
Hey hey guys. I believe it has something to do with CIS. " COM Internet Services Proxy (a feature that is part of Windows 2000 that allows a server to accept DCOM requests tunneled over HTTP)" " The list of supported transports is as follows: Local RPCncalrpc TCP/IP ncacn_ip_tcp SPX