Home | About Us | FAQ | Signature Downloads | All Projects | Submit a Signature | Mailing Lists | Feeds | Open Job Board | Sponsors | Documentation

  • RSS Latest Docs

    • 2003394
    • SnortConfSamples
    • FastFluxDNSResponseDetection
    • 2007634
    • DilipPatel
    • TestTest123
    • 2003642
    • 2007588
    • 2007688
    • 2007706
  • RSS Latest Sigs

    • VIRUS/TROJAN_PRG
    • VIRUS/TROJAN_Win32.Pakes
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • WEB/WEB_Neosploit
    • current-sids.txt
    • VIRUS/TROJAN_Win32.Pakes
  • Recent Comments

    • Buck on Guard.zip Phish, Very targeted, Sig Available
    • Lance on Guard.zip Phish, Very targeted, Sig Available
    • akgunk on Guard.zip Phish, Very targeted, Sig Available
    • Bill475382635','199440348billy@msn.com','','20.134.10.131','2008-05-20 20:38:34','2008-05-20 20:38:34','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:38:34', '2008-05-21 20:38:34', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
    • Bill370791230','617930106billy@msn.com','','104.199.69.73','2008-05-20 20:03:22','2008-05-20 20:03:22','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:03:22', '2008-05-21 20:03:22', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
  • Recent Posts

    • Rule & Firewall Updates Re-enabled
    • I’m Leaving Bleeding Threats!
    • Encrypted Storm Sigs
    • Windows 98 Snort Signature
    • E-Jihad Tool Sigs
  • « Bandook Trojan Sigs Posted
    Storm worm email rules »

    New MS DNS Vulnerability!

    ISC has posted new information regarding the MS DNS compromises we saw last week.

    http://isc.sans.org/diary.html?storyid=2627

    There is a BO in the MS DNS RPC service.

    http://www.microsoft.com/technet/security/advisory/935964.mspx

    MS is developing a patch. Workarounds are to disable remote management over RPC or block inbound ports 1024 to 5000.

    I know I don’t have to say it to the bleeding edge community, but I will anyway in case this gets forwarded on: :)

    Don’t ever leave a windows box exposed to the internet! You’ll regret it. Maybe not today, maybe not tomorrow, but soon, and for the rest of your life. [1]

    I’ve dropped sigs 2003539 and 2003240. They’re no longer necessary. Many thanks to everyone that reported hits, it was very helpful. We do not have enough information yet to write a signature for the vulnerability. Once we do we’ll post as soon as possible. If anyone happens to talk to MS, or gets hints of information via other sources, please let us know!

    Matt

    [1] en.wikipedia.org/wiki/Casablanca_(film)

    This entry was posted on Friday, April 13th, 2007 at 2:36 pm and is filed under General, New Rules. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    2 Responses to “New MS DNS Vulnerability!”

    1. jonkman Says:
      April 13th, 2007 at 2:52 pm

      http://research.eeye.com/html/alerts/zeroday/20070407.html

    2. Paris Hilton Sex Tape Video - Paris Hilton Exposed Says:
      February 1st, 2008 at 9:10 pm

      interesting Paris hilton sex tape outtake…

      Recently leaked footage of the new Paris Hilton sex tape. …

    Leave a Reply

    You must be logged in to post a comment.

    Entries (RSS) and Comments (RSS)
    Copyright © 2007 Bleeding Edge Threats.
    All trademarks and copyrights on this page are owned by their respective owners. Snort® is a registered trademark of Sourcefire, Inc.