Vulnerability Development mailing list archives

[Fwd: rpcclient 2.0.5a crashed services.exe]


From: BlueBoar () THIEVCO COM (Blue Boar)
Date: Wed, 15 Dec 1999 21:03:31 -0800


".rain.forest.puppy." wrote:

The 2.0.5a crashed services.exe by doing:
smb: \> srvshares
cli_pipe: return critical error. Error was code 0
The machine is in a very odd state now (can't do anything, no BSOD,
trying to reboot...can't seem to...finally did...

This is RFPoison, exactly.  Microsoft has released MS99-055, which fixes
this problem, but I would be willing to bet it still leaves all the other
RPC problems wide open--i.e. they patched against THIS SPECIFIC attack
only, rather than fix RPC as a whole.

Cheers,
.rain.forest.puppy.

Thanks for the info RFP.  It looks to me like the Samba rpcclient code is
going to be a very useful research tool.

                                                        BB


Current thread: