This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS06-034, MS06-035, and MS06-036 exploits available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1471
Last Updated: 2006-07-24 20:28:35 UTC
"We have been made aware of publicly available exploit code for MS06-034, MS06-035, and MS06-036. If you haven't already patched for these vulnerabilities you should take immediate action.

For more information on those vulnerablies here are links to the original diary entries for them.

http://isc.sans.org/diary.php?storyid=1473 (MS06-034)

http://isc.sans.org/diary.php?storyid=1471 (MS06-035)

http://isc.sans.org/diary.php?storyid=1472 (MS06-036)

I have not tested any of the exploits yet. I do not plan to provide the urls or even a hint as to where to get the exploits…"

:ph34r:
FYI…

- http://isc.sans.org/diary.php?storyid=1522
Last Updated: 2006-07-28 23:05:44 UTC
"…Microsoft posted a blog* entry this afernoon containing information about their assessment of recent reports of a vulnerability which was not addressed in MS06-035. It appears that the current proof of concept is limited to a denial of service attack and is not currently being observed as an attack vector. Microsoft reports that they have not identified any possibilities that the issue could allow remote code execution. We recommend that you assess your particular situation. Blocking ports 135-139, 445 is already a best practice. Whitelist IPs that may need these ports, but remember to limit your exposure from your road warrior/home office users. We expect that Microsoft will release a patch on August 8 to address this current threat."

* http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx

:huh: