lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <2210707B.1A6D734F@mail.gmail.com> From: jackhammer at gmail.com (Paul Tinsley) Subject: Windows Lsasrv.dll RPC buffer overflow Remote Exploit (MS04-011) I haven't seen much discussion about this one other than here: http://www.incidents.org/diary.php?date=2004-04-25&isc=24f2410ad7a5b786b009d9226c908b92 and I just figured I would pass along that this one is real and does work. We setup some vmware sessions awhile ago and tested it against a W2K SP4 box with no success, but a W2K SP4 box with all patches except MS04-011 and MS04-012 was a successful target. So patching is probably a good idea if you haven't already done so.