lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [thread-next>] [month] [year] [list]
From: mcw at wcd.se (bashis)
Subject: win2kup2date.exe ?

Hi

Anyone heard about a file called "win2kup2date.exe" ?
(Google says nothing found..;)

I did a controlled test with a XP Pro box w/o patches on Inet
and this little thingy came on my testbox thrue some sort of RPC exploit,
tftp'ed down this file from connecting machine, started with SYSTEM,
and tries to connect up to IRC.

McAfee Virusscan Enterprise v8.0i with latest DAT's didn't find
any strange with this file..

That was actually my test, v8.0 of McAfee virusscan have a future of
"buffer overflow protection", it stopped the wellknown public RPC/DCOM
exploit, but not the exploit that putted "win2kup2date.exe" on my testbox.

Well, so mutch for the new "buffer overflow protection" future.. crap.. ;)

Have a nice day
/bashis


Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux