Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 14 of 14

This is a discussion on MS Issues Emergency Patch !!! in the Open Discussion & Chit-chat forum
A critical flaw has been found that allows remote code execution , through a specifically crafted RPC request against the Server Service (i.e. this is ...

  1. #1
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775

    Exclamation MS Issues Emergency Patch !!!

    A critical flaw has been found that allows remote code execution, through a specifically crafted RPC request against the Server Service (i.e. this is a SMB exploit). MS has issued an "out-of-band" patch to immediately fix this, as all versions of Windows are vulnerable.

    Windows 5.xx: Completely Vulnerable/Critical (No authentication required)
    Windows 6.xx: Partially Vulnerable/Important (The attacker would need appropriate authentication credentials)

    Firewalls can block this, but only if they're configured to block SMB requests. This means that most computers in a LAN are vulnerable to each other, should an exploit be deployed in such a way that it can cross the network's firewall (i.e. delivered via infected laptops or an email-based worm).

    This is currently being exploited in the wild

    Patch today, before certain doom strikes!

    BTW, despite what Microsoft Security Bulletin MS08-067 says, this patch can be Hotpatched...

    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  2. #2
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Windows 5 and 6, Man you should be Using XP or Vista
    -------------------------
    the_ancient
    MP Technology Group

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Let's see...

    I got a Win98SE proxy server, three W2K desktops, a XP and Vista lappy[s].

    Got all my bases covered!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by Vin DSL View Post
    Let's see...

    I got a Win98SE proxy server,
    That is sooo last decade
    -------------------------
    the_ancient
    MP Technology Group

  5. #5
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    At 3:00 this afternoon they started blocking unpatched computers from the campus network at work--they didn't want this one floating around over the weekend. Anyone with an unpatched computer now gets an IP address in the 10.10.*.* range instead of a public IP when they hit the DHCP servers for a lease renewal and they get blocked from doing anything online except hitting our "why am I seeing this page" site and Windows Update.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  6. #6
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,304
    Just curious, without me going and studying the vulnerability, how does the DHCP server know the patch hasn't been applied?
    Good luck

  7. #7
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    The DHCP server doesn't. Our Information Security Office routinely scans computers connected to our network for known vulnerabilities. When it finds one it blacklists it. When the blacklisted computer tries to renew its lease, the DHCP server sees that it is blacklisted and hands out an internal-only IP. Blacklisted computers get rescanned every hour or so, so once the scanner sees the computer is patched it removes the blacklisting and during the next lease renewal (blacklisted IPs have very short leases) the computer gets its old IP back.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  8. #8
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,304
    Hahaa! Neat!
    Good luck

  9. #9
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by the_ancient View Post
    That is sooo last decade
    Proxy servers?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  10. #10
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by Vin DSL View Post
    Proxy servers?
    no win98.... you know 2008 - 1998 == 10years or 1 decade
    -------------------------
    the_ancient
    MP Technology Group

  11. #11
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by the_ancient View Post
    no win98.... you know 2008 - 1998 == 10years or 1 decade
    I'm also using W2K which is 8 years old, XP which is 7 years old, and Vista which is 3 years old....

    And, my production site (JagPC) and private sites (home) are using Linux which is 17 years old.

    What's your point, stupid?

    n/m

    You probably got older pron than my various OSes... and that still gets you off in a Kleenex which is 84 years old!
    Last edited by Vin DSL; 10-26-2008 at 10:14 PM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  12. #12
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by Vin DSL View Post
    I'm also using W2K which is 8 years old, XP which is 7 years old, and Vista which is 3 years old....

    And, my production site (JagPC) and private sites (home) are using Linux which is 17 years old.

    What's your point, stupid?

    n/m

    You probably got older pron than my various OSes... and that still gets you off in a Kleenex which is 84 years old!
    Sounds like some one needs to buy himself a hooker
    -------------------------
    the_ancient
    MP Technology Group

  13. #13
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by the_ancient View Post
    Sounds like some one needs to buy himself a hooker
    Yeah, sure!

    Then you'll say I'm using a 23 year-old trick instead of a 5 year-old, like you...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  14. #14
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by Vin DSL View Post
    Yeah, sure!

    Then you'll say I'm using a 23 year-old trick instead of a 5 year-old, like you...
    naaa I wait until they are legal..... 16 here in the great state of Indiana
    -------------------------
    the_ancient
    MP Technology Group

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •