Penetration Testing mailing list archives

Re: MS08-067 - Where can I find an exploit for this?


From: Tim Brown <tmb () 65535 com>
Date: Fri, 24 Oct 2008 22:41:11 +0100

On Friday 24 October 2008 17:27:06 Salvador III Manaois wrote:
milw0rm's got one:

http://www.milw0rm.com/exploits/6824
http://milw0rm.com/sploits/2008-ms08-067.zip


I know that a few people have had problems with the public POC for this 
vulnerability.  In my case rather than figure out why VS wouldn't happily 
compile it, I ended up patching samba/rpcclient.  I'm not making the patch 
available publicly but I wrote up a short piece on the essentials of what I 
did here: http://www.nth-dimension.org.uk/blog.php?id=72.  It should be 
fairly easy to reproduce the POC at least if you have even minimal C skills.

Cheers,
Tim
-- 
Tim Brown
<mailto:tmb () 65535 com>

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


Current thread: