Penetration Testing mailing list archives

Re[2]: New VNC Attack tutorial


From: Thierry Zoller <Thierry () Zoller lu>
Date: Sat, 17 Jun 2006 13:11:03 +0200

Dear Luchino Samel,


It raises the limit of HALF-OPEN connections in Windows XP SP2,
Microsoft limited the stack to only be able to have max 10 half open
tcp connections, which is of course very bad for scanning. Hence
you have to apply the patch before the scan...btw it's a general
recommendation for windows xp sp2.

-- 
http://secdev.zoller.lu
Thierry Zoller
Fingerprint : 5D84 BFDC CD36 A951 2C45  2E57 28B3 75DD 0AC6 F1C7


------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: