News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
May 21, 2013, 22:18:26
Pages: [1]   Go Down
  Print  
Topic: Vista/2008/Windows7 SMB2 BSOD 0-Day  (Read 1971 times)
0 Members and 1 Guest are viewing this topic.
« on: September 08, 2009, 08:42:11 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7319



FYI...

Vista/2008/Windows7 SMB2 BSOD 0-Day
- http://isc.sans.org/diary.html?storyid=7093
Last Updated: 2009-09-08 13:09:06 UTC - "... vulnerability affecting Microsoft SMB2* can be remotely crashed with proof-of-concept code that has been published yesterday and a Metasploit module is out. We have confirmed it affects Windows 7/Vista/Server 2008. The exploit needs no authentication, only file sharing enabled with one 1 packet to create a BSOD. We recommend filtering access to port TCP 445 with a firewall. Windows 2000/XP are NOT affected by this exploit..."
* http://en.wikipedia.org/wiki/Server_Message_Block#SMB2

 Shocked
« Last Edit: September 08, 2009, 08:47:47 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #1 on: September 08, 2009, 18:37:13 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7319



FYI...

Microsoft Security Advisory (975497)
Vulnerabilities in SMB Could Allow Remote Code Execution
- http://boards.cexx.org/index.php?topic=11831.new#new

- http://www.symantec.com/connect/blogs/bsod-and-possibly-more
September 15, 2009

 Exclamation
« Last Edit: September 15, 2009, 19:00:08 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #2 on: September 17, 2009, 01:36:51 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7319



FYI...

SMB2 remote exploit released
- http://isc.sans.org/diary.html?storyid=7141
Last Updated: 2009-09-16 21:15:36 UTC - "... 0-day vulnerability in SMB2 on Windows Vista and Server 2008 operating systems... Yesterday a well known security company added a module for their exploitation product. The module contains the remote exploit for this vulnerability – in other words, any user running this tool can get full access to affected machines. If the exploit is stable enough, it can _very easily_ be used in a worm, so it can potentially be devastating. So, if you are running a Windows Vista or Server 2008 machine (Windows 7 RTM is not affected, RC *is*), be sure you apply one of workarounds listed by Microsoft (they are not perfect, but they can help), available here*..."
* http://www.microsoft.com/technet/security/advisory/975497.mspx

- http://www.theregister.co.uk/2009/09/16/windows_vista_exploit_released/
16 September 2009

 Evil or Very Mad Shocked Evil or Very Mad
« Last Edit: September 17, 2009, 02:57:52 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #3 on: September 17, 2009, 14:16:10 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7319



FYI...

Microsoft Security Advisory (975497)
Vulnerabilities in SMB Could Allow Remote Code Execution
- http://boards.cexx.org/index.php?topic=11831.new#new
"...automated Microsoft Fix it solution" available.

 Exclamation
Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #4 on: September 29, 2009, 04:51:04 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7319



FYI...

Metasploit exploit module released
- http://www.symantec.com/security_response/threatconlearn.jsp
"... tracking a remotely exploitable vulnerability affecting the SMB kernel component ('srv2.sys'). Microsoft has reported that Windows Vista (SP1 and SP2) and Windows Server 2008 are affected. Reportedly, some beta builds of Windows 7 may also be affected.

On September 28, 2009, a remote code-execution exploit Metasploit module was released publicly. Attackers may be able to convert this module into other exploits and use it in the wild. We strongly advise users to block TCP port 445 immediately until patches are available. The researcher who discovered the flaw has stated that file sharing must be enabled for the issue to be exploited. Unless file sharing is explicitly required, users should disable it..."

- http://www.microsoft.com/technet/security/bulletin/MS09-050.mspx
Updated: October 14, 2009

- http://www.microsoft.com/technet/security/advisory/975497.mspx
Updated: October 13, 2009

 Shocked
« Last Edit: November 05, 2009, 11:24:58 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
 
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.406 seconds with 20 queries.