Intellipute
Security News
Title: Buffer Overrun In RPCSS Service Could Allow Code Execution (824146) Date: September 10, 2003 Software: Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Server(r) 4.0 Microsoft Windows NT Server 4.0, Terminal Server Edition Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Impact: Run code of attacker's choice Max Risk: Critical Bulletin: MS03-039

Microsoft encourages customers to review the Security Bulletins at:

http://www.microsoft.com/technet/security/bulletin/MS03-039.asp http://www.microsoft.com/security/security_bulletins/MS03-039.asp - - -----------------------------------------------------------------

Issue: ======

The fix provided by this patch supersedes the one included in Microsoft Security Bulletin MS03-026.

Remote Procedure Call (RPC) is a protocol used by the Windows operating system. RPC provides an inter-process communication mechanism that allows a program running on one computer to seamlessly access services on another computer. The protocol itself is derived from the Open Software Foundation (OSF) RPC protocol, but with the addition of some Microsoft specific extensions.

There are three identified vulnerabilities in the part of RPCSS Service that deals with RPC messages for DCOM activation- two that could allow arbitrary code execution and one that could result in a denial of service. The flaws result from incorrect handling of malformed messages. These particular vulnerabilities affect the Distributed Component Object Model (DCOM) interface within the RPCSS Service. This interface handles DCOM object activation requests that are sent from one machine to another.

An attacker who successfully exploited these vulnerabilities could be able to run code with Local System privileges on an affected system, or could cause the RPCSS Service to fail. The attacker could then be able to take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges.

To exploit these vulnerabilities, an attacker could create a program to send a malformed RPC message to a vulnerable system targeting the RPCSS Service.

Microsoft has released a tool that can be used to scan a network for the presence of systems which have not had the MS03-039 patch installed. More details on this tool are available in Microsoft Knowledge Base article 827363. This tool supersedes the one provided in Microsoft Knowledge Base article 826369. If the tool provided in Microsoft Knowledge Base Article 826369 is used against a system which has installed the security patch provided with this bulletin, the superseded tool will incorrectly report that the system is missing the patch provided in MS03-026. Microsoft encourages customers to run the latest version of the tool available in Microsoft Knowledge Base article 827363 to determine if their systems are patched.

Mitigating Factors: ==================== - Firewall best practices and standard default firewall configurations can help protect networks from remote attacks originating outside of the enterprise perimeter. Best practices recommend blocking all ports that are not actually being used. For this reason, most systems attached to the Internet should have a minimal number of the affected ports exposed.

Risk Rating: ============ - Critical

Patch Availability: =================== - A patch is available to fix this vulnerability. Please read the Security Bulletins at http://www.microsoft.com/technet/security/bulletin/MS03-039.asp http://www.microsoft.com/security/security_bulletins/MS03-039.asp for information on obtaining this patch.

Acknowledgment: =============== - eEye Digital Security (http://www.eeye.com/html) - NSFOCUS Security Team (http://www.nsfocus.com) - Xue Yong Zhi and Renaud Deraison from Tenable Network Security (http://www.tenablesecurity.com) for reporting the buffer overrun vulnerabilities and working with us to protect customers. - - ----------------------------------------------------------------- THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.

-----BEGIN PGP SIGNATURE----- Version: PGP 8.0.2 iQEVAwUBP19PE40ZSRQxA/UrAQFL2ggAk84V2SkEsj8r0xW6JoxE9ojVFp8kQLWS SMYMXP6iEONzJzUGcoX8OLDWG5ncSoJVOSM+84PUCOAFnIZs8eZV8MiOdjm/j2yO Fv+0bw6foQbsyvFT9Kcckrj/DJAIEnu5EMwVcU1jlkP1rIj6JXaZdC78jpHson2y AdxBM8altRg1aKplWYVe5vOV0Ya92KUkbKy0khv9xKgNO/PPbno4AdBzkk5s7hqy NNnhi+lbdZBubzhQkvG+Wj3bAA/onj7SdTAKXuaLEB61c5gDsznwV+d+tHYbZjdm 3BAhoL+b34yteRa3wJrMxgz6+KJLDpUvEUW9DYU9Mlscl3+d1StbNw== =2u0i -----END PGP SIGNATURE----- *******************************************************************
Virus News
Apache_mod_ssl Worm Alert
Reference Bugtraq ID 5363, Subj: OpenSSL SSLv2 Malformed Client Key Remote Buffer Overflow Vulnerability Risk Impact High Affected Components Red-Hat: Apache 1.3.6, 1 3 9, 1.3.12, 1.3.19, 1.3 20, 1.3 22, 1.3 23, 1.3.26 . SuSe: Apache 1.3.12, 1.3 17, 1.3 19, 1.3.20, 1.3 23 . Mandrake: Apache 1.3 14, 1.3.19, 1.3.20, 1.3 23 . Slackware: Apache 1.3 26 . Debian: Apache 1.3.26
Overview The Symantec DeepSight Threat Analyst Team has learned of the existence of a new exploit for the OpenSSL SSLv2 Malformed Client Key Remote Buffer Overflow vulnerability, targeting Apache Web servers hosted on various Linux platforms. This also includes a number of peer-to-peer capabilities, which allow it to communicate with other clients, and participate in a Distributed Denial of Service (DDoS) network. To perform these activities, the exploit code listens on UDP port 2002. The exploit further exhibits worm behavior in that indications are that, once it is setup, it scans and attempts to propagate by infecting other vulnerable systems. It is confirmed through various sources that this worm is in the wild and actively attacking other servers. Over 3500 IP addresses have been recorded as being the source of scanning and associated activity, according to DeepSight Threat Management System data and other sources.

Important Links

WebMail
Access Numbers
Our Dial Up Portal
Web Site Administration
Computer Consulting
Pre Paid Legal Insurance


 

Full Service Information Technology Provider

WE SPECIALIZE IN THE TOTAL SOLUTION

FROM CONNECTIVITY TO DEVELOPMENT TO COMPUTERS

With just one call we do it ALL!

Welcome to Intellipute.

Intellipute is a cutting edge technology company that can service all of your  Information and Technology needs.  

We offer a single point of contact for: internet connectivity,  web hosting,domain name registration, networking and development solutions  ranging from custom desktop and client server applications to internet/intranet  solutions.

Our expert staff has a very diverse skill set and is able to help  you in many different ways.  Whether you need an online catalog,  to sell your products, or you need marketing demographics on the products you wish  to sell, we can help.

Call 1-866-404-7111 to sign up today

E-mail: kathy@intellipute.net


Pay me securely with your Visa or MasterCard through PayPal!

468x60 April 2002
Stamps.com

Banner 10000062

Are the other ISP's prices causing  your eyes to bug out.  Well give us a call and we will put a big smile on your face!


About Our Products

Our products include: Web Design
Domain Registration
Domain Hosting
Search Engine Submission
Custom Servers
Custom PC
Intelliassets
Intellihelper
Intellischeduler
Network Administration
Custom Applications
Database Creation
Database Administration


About Our Services

Our services include:
Intellipute LLC is a global company. We have ISP Customers all over the World and Consulting Customers in 7 states. We can administer your network from our office remotely and you can be located anywhere in the USA. We do Application and Web Development for customers all over the USA. We can travel to you to gather the information, then go back to our offices and write the application, then if necessary we can travel back to your location to implement the work. Everything else is done remotely.

 

© 2004 Intellipute. All rights reserved. Programming and Hosting provided by Intellipute.