Full Disclosure mailing list archives
RE: RE: Probable new MS DCOM RPC worm for Windo ws
From: "Schmehl, Paul L" <pauls () utdallas edu>
Date: Fri, 26 Sep 2003 09:40:54 -0500
-----Original Message----- From: Ferris, Robin [mailto:R.Ferris () napier ac uk] Sent: Friday, September 26, 2003 8:37 AM To: 'full-disclosure () lists netsys com' Subject: RE: [Full-disclosure] RE: Probable new MS DCOM RPC worm for Windo ws I have not yet verified if the files were installed or not and thats a very good point. I didnt and still dont know what files it changed or installed for the ms03-026. What are they?
You can go into the registry and see that. Go to HKEY_LOCAL_MACHINE\Software\Microsoft\Updates\(Your OS)\(Next SP)\(patch in question) and you will find the filenames (and their properties) that were replaced by the patch. For example, on XP: HKEY_LOCAL_MACHINE\Software\Microsoft\Updates\Windows XP\SP2\KB824146k\Filelist\0 shows that ole32.dll was replaced by the MS03-039 patch and it has a build checksum of 1248ac, a build date of Mon Aug 25 13:53:42 2003 and a version number of 5.1.2600.1263 and it's located in C:\WINDOWS\System32. You can then go to that directory and check the file properties to verify that it matches what's in the registry. Just FYI, the two other files that were replaced are rpcrt4.dll and rpcss.dll. MS03-026 replaced the same three files. Paul Schmehl (pauls () utdallas edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/~pauls/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Schmehl, Paul L (Sep 26)
- Re: RE: Probable new MS DCOM RPC worm for Windo ws Gary Flynn (Sep 26)
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Jay Sulzberger (Sep 26)
- <Possible follow-ups>
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Schmehl, Paul L (Sep 26)
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Jerry Heidtke (Sep 26)
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Schmehl, Paul L (Sep 26)
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Schmehl, Paul L (Sep 26)
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Schmehl, Paul L (Sep 26)
- Re: RE: Probable new MS DCOM RPC worm for Windows Cael Abal (Sep 26)
- Re: RE: Probable new MS DCOM RPC worm for Windows Paul Schmehl (Sep 26)
- Re: RE: Probable new MS DCOM RPC worm for Windows Karl DeBisschop (Sep 27)
- Re: RE: Probable new MS DCOM RPC worm for Windows Brent J. Nordquist (Sep 29)
- Re: RE: Probable new MS DCOM RPC worm for Windows Cael Abal (Sep 26)
- RE: RE: Probable new MS DCOM RPC worm for Windo ws Jay Sulzberger (Sep 26)