Page 1 of 1 1
Topic Options
#118556 - 2004-04-24 01:19 AM OT: MS04-011 exploit tool in the wild
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11624
Loc: CA
This is to notify you that an exploit tool has been released for the "SSL/PCT 1.0" vulnerability described in the MS04-011 bulletin. After lab testing, It has been verified that an unpatched installation of IIS with an SSL certificate is vulnerable to this tool, which grants an attacker a remote command shell on the victim system with "SYSTEM" privileges. In addition, the tool induces the victim machine to initiate the command shell connection back to the attacker: since the inbound delivery of the attack occurs on a standard HTTP/SSL port (TCP/443) and the returned shell is a new outbound connection from the server, this attack will work through firewalls that permit outbound connections from the server.

Top
#118557 - 2004-04-28 09:54 AM Re: OT: MS04-011 exploit tool in the wild
Trackz Offline
Fresh Scripter

Registered: 2004-03-18
Posts: 37
Loc: Rotterdam, The Netherlands
Doc, What is your source?
Like to read a little more, next to the symantec.mcafee reports about this

Top
#118558 - 2004-05-01 06:32 AM Re: OT: MS04-011 exploit tool in the wild
Atoyot Offline
Fresh Scripter

Registered: 2003-07-23
Posts: 13
Loc: Houston, Texas
We actually got a call from our Microsoft rep warning us about this tool and telling us to install this patch. If they are worried, then I am worried.

Atoyot

Top
#118559 - 2004-05-01 10:59 AM Re: OT: MS04-011 exploit tool in the wild
Trackz Offline
Fresh Scripter

Registered: 2004-03-18
Posts: 37
Loc: Rotterdam, The Netherlands
Ok, We got hit yesterday, on some unpatched systems in our network. Some of them were pretty critical machines, that we accidently forgot to do. *oops*
Probably this code helped the creator of an more advanced exploit. ( http://www.k-otik.com/exploits/04292004.HOD-ms04011-lsasrv-expl.c.php )
Fully patched now.


Edited by T_Hoek (2004-05-01 11:00 AM)

Top
Page 1 of 1 1


Moderator:  Arend_, Allen, Jochen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 132 anonymous users online.
Newest Members
MaikSimon, kvn317, kixtarts2025, SERoyalty, mytar
17872 Registered Users

Generated in 0.041 seconds in which 0.016 seconds were spent on a total of 13 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org