[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20030729035049.22037.qmail@www.securityfocus.com>
Date: 29 Jul 2003 03:50:49 -0000
From: <sk@...n-associates.net>
To: bugtraq@...urityfocus.com
Subject: Re: DCOM RPC exploit (dcom.c)
In-Reply-To: <20030727025321.64988.qmail@...11001.mail.yahoo.com>
>One glitch is that the exploitation is not very
>stealth. All RPC/COM based functions stop working
>completely after exploitation and fail to heal until
>the machine is restarted. Many of these functions are
>quite visible and easily noticeable(drag&drop,
>clipboard, property sheets, etc., for example). This
>happens without exception.
If the shellcode exit via ExitThread(), RPCSS will not die, everything
rock as usual, and you can run the exploit over and over again.
sk
Powered by blists - more mailing lists