Web Hosting Talk







View Full Version : Win2K Exploit


Jay Suds
08-27-2002, 12:44 PM
This came through my email box today:


-----Original Message-----
From: Kevin Gennuso [mailto:goosey@ICUBED.COM]
Sent: Tuesday, August 27, 2002 10:02 AM
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Subject: MS02-045 exploit is out


Hi all,

I haven't seen much noise on this list about MS02-045 (Unchecked Buffer in Network Share Provider Can Lead to Denial of Service (Q326830)), but the implications are very nasty. Any unpatched WinNT/2K/XP or .NET machine on your network that's listening on port 139 and/or 445 can be crashed in about two seconds with a malformed SMB packet. I highly disagreed with Microsoft's assessment that this was only a "moderate" threat level to intranet and desktop systems because the exploit is so easy to perform.

It was bad enough in theory, but now a script-tot friendly GUI version of the exploit has been posted on PacketStorm, and it works against all of the above. You can try for yourself at http://packetstorm.decepticons.org/0208-exploits/SMBdie.zip

We worked through the weekend to get a large percentage of our boxen patched - you may have to do the same.

The old "WinNuke" from the evil days of Win95 is back.

Thanks for listening,

Kevin


If you're running Win2K / .NET internet servers, make sure you are blocking ports 139 / 445 at your router / firewall level. If not, make sure you install the patch at http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS02-045.asp ....

combs
08-27-2002, 02:12 PM
Thank you for the info. We will remember that.

dreamrae.com
08-28-2002, 03:37 PM
lol...this cant be true, h/o crashing ex's box....

anantatman
08-29-2002, 02:59 AM
i think it comes with the windowsupdate..

if you have windowsupdate's automatic update and restart, you should be good

ntwaddel
08-29-2002, 03:18 AM
i have that program :D

Studio64
08-29-2002, 03:43 AM
In a general webhosting security sense...

You show me a Win2k host that has NetBIOS enabled and I promise they have a great deal more problems that this little thing.

Heck.. Show me any Windows computer running NetBIOS and I'll show you a problem.

anantatman
08-29-2002, 03:53 AM
hahah

RackMy.com
08-29-2002, 11:09 AM
You show me a Win2k host that has NetBIOS enabled and I promise they have a great deal more problems that this little thing. You read my mind!!!

It's amazing though how many colo customers we do work for that always enable NetBIOS and File/Print sharing on a Public NIC.

Haley
08-29-2002, 01:29 PM
LOL. This must be from some spammer.

Jay Suds
08-30-2002, 12:22 AM
Originally posted by Haley
LOL. This must be from some spammer.

Nope, not a spammer. The message came through NTBUGTRAQ, which is a highly moderated NT / Win2K bug mailing list.

And RackMy is right ... anyone with NetBIOS enabled will have a lot more problems than just this ... it's just general good sense that you either need to disable NetBIOS or completely block port 139 / 445 with any Windows box.

RackMy.com
08-30-2002, 04:23 AM
This must be from some spammer.I am confused, why would you say that?