This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS05-051 exploit info and rumors

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=759
Last Updated: 2005-10-12
"Patch yesterday folks. So far we're aware that an MS05-051 exploit is in the hands of immunitysec Canvas customers - "October 11, 2005: MS05-051 (MS DTC) Trigger for the bug in MS DTC on Windows 2000"
In addition we're seeing reports of non-specific exploit warnings from managed security service providers to their customers. And some rumors.
McAfee Vulnerability Information says that they have protection against exploits of MS Vulnerability MS05-051, "Entercept's Generic Buffer Overflow Protection protects against code execution that may result from exploiting this vulnerability."
- http://vil.nai.com/vil/content/v_136473.htm

…Here's some pre-vuln announcement facts, see the DShield data on Port 3372 scanning, ymmv. We'll post anything else that's specific and critical when we get it…"
- http://isc.sans.org/port_details.php?port=3372

:ph34r: :ph34r:
FYI…

MS05-051 exploit spotted by Trend Micro
- http://isc.sans.org/diary.php?storyid=769
Last Updated: 2005-10-18 02:51:35 UTC
"Trend Micro reports that they spotted a POC for MS05-051 in the wild. They found it included as a new exploit in other malware. We don't have any details yet beyond what can be found in at Trend Micro. If you find a copy of this malware, please forward it. Trend Micro states that the malware was written in Visual Basic, which usually indicates some low skilled bot-kid. Kind of odd to see it surface this way, but having it included as a new warhead in existing malware matches past patterns. Trend Micros virus statistics do not report any "captures" of this exploit in the wild. Not exactly sure if this is just a lab sample, or if it was actually seen in the "wild". We will update this diary as we learn more."
- http://www.trendmicro.com/vinfo/virusencyc…=TROJ_SSPLOIT.A

:ph34r: