Welcome! Register for a free account (or login) > How does it work?
|
|
![]() ![]() |
Sep 8 2008, 06:29 PM
Post
#1
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 4,573 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3 |
FYI...
- http://isc.sans.org/diary.html?storyid=4997 Last Updated: 2008-09-08 23:45:34 UTC ...(Version: 5) - "In June we talked about a SCADA buffer overflow vulnerability discovered by CORE that affected the CitectSCADA product. It could allow a remote un-authenticated attacker to force DoS or to execute arbitrary code on vulnerable systems. The patch was available at that time, so if you have not patched or taken extreme security precautions and countermeasures yet, you have another reason to do so today! This weekend, Kevin Finisterre has published a working exploit in the form of a Metasploit (MSF) module that demosntrates how critical this vulnerability aginst the ODBC service is. The original CORE advisory* details the vulnerability ( http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-2639 )... our DShield service shows a peak in the wild associated to the target vulnerable port (TCP/20222)**." * http://www.coresecurity.com/content/citect...e-vulnerability ** http://www.dshield.org/port.html?port=20222 "...a Snort signature to detect the SCADACitect ODBC exploit has been released ..." - http://www.digitalbond.com/index.php/2008/...or-citect-vuln/ |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
7 | Skandranon | 291 | 20th February 2010 - 12:47 PM Last post by: Skandranon |
|||
![]() |
2 | HellsGate | 176 | 31st January 2010 - 01:04 AM Last post by: HellsGate |
|||
![]() |
1 | Jason Pr0 | 184 | 25th January 2010 - 03:08 AM Last post by: paws |
|||
![]() |
1 | saddler64 | 343 | 13th December 2009 - 03:31 PM Last post by: Ztruker |
|||
|
Time is now: 19th March 2010 - 11:57 AM |