This was initaly mentioned by r8devil here
http://www.antionline.com/showthread...hreadid=246183
but I felt his title din't convay the seriousness of this issue.
Ok it looks like RPC is broken badly, I have had reports this week that we have had a spike of scans on port 135 and this is why.
Basicly a remot exploit of RPC will allow an attacker t oexecute any code with systems access. Now this is mitagated a littel by safe computeing (turn off RPC if not needed) or proper fire wall setup (block port 135) unless like my office you use RPC in some of your remote administration...we havent been exploited yet as the attacks have hit our web system with RPC turned off.
Here is a reg artical that explains the exploit.
http://www.theregister.com/content/55/31797.html
and here is a link to the fix
http://www.microsoft.com/technet/tre...n/MS03-026.asp




Reply With Quote