Nov. 16th, 2006

MS06-070

Nov. 16th, 2006 05:43 am
foxgrrl: (Default)
As you are all well aware, yesterday was Microsoft Patch Tuesday. One of the vulnerabilities, was basically an anonymous remote root exploit against the default install of Windows 2000 (and maybe XP too). There isn't any POC code floating around on the net yet, so I wrote some to settle an argument.

I'm wondering now if I should release it publicly, or sell it to the highest bidder, or something. It currently does require a Windows Active Directory server, but if I work on it some more, I think I can make it work without requiring a separate windows server. (i.e. to work on Linux/*BSD/OSX alone). (Also, only Win2K targets so far.)

The MS advisory on this, less than useful as always: http://www.microsoft.com/technet/security/Bulletin/MS06-070.mspx

And the much more detailed - if remarkably vague in areas - eEye advisory on it: http://research.eeye.com/html/advisories/published/AD20061114.html
There's just enough information to find the vulnerability, and a hint as to how to trigger it, but not any details like about how the JoinOptions flag [arg_6] needs to be 0x01 (you'll want to use RPC function 0x16).

Oh yeah, I was going to mention, that this is also the first exploit I've written in the MSF3. I must say that the NDR and DCERPC libraries made this exploit so much faster and easier to write. (Easier to write than giant blobs of raw binary data, which is how I typically write stuff.)
foxgrrl: (Default)
So, the deadline for this weekend is fast approaching (I'd say, in a little bit more than 24 hours). And I haven't decided yet whether to drive up to Portland, OR to visit [livejournal.com profile] amberite, [livejournal.com profile] teaotter, [livejournal.com profile] heron61, [livejournal.com profile] kengr, [livejournal.com profile] pdxsharkey, [livejournal.com profile] gidget23, and whomever else I've forgotten that lives up there. I might even make it to Orycon or something.

I've never been to Portland before, so this would be a new and frightening experience for me, zomg! It may forever change who I am, or something.

The alternatives are to stay home this weekend, sleep, fix my computer, finish repainting the bathroom, maybe read some books I never have time to read, or to listen to some CDs that I haven't even had the time to remove from their plastic shrinkwrap yet. (Oh yeah, and work on some exploits, or posting of my photos.) Nyah is going to be out of town this weekend too, so it's just me for now.

Profile

foxgrrl: (Default)
foxgrrl

May 2023

S M T W T F S
 123456
78910111213
14151617181920
212223242526 27
28293031   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 22nd, 2026 07:52 pm
Powered by Dreamwidth Studios