OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Dailydave] ms04-031 pre-auth ??

From: Matt Hargett (mattuse.net)
Date: Mon Oct 18 2004 - 04:54:21 CDT


Sinan Eren wrote:
> http://www.microsoft.com/technet/security/bulletin/ms04-031.mspx
>
> We have located the vulnerable function and just recently wrote the
> CANVAS module for it but all our tests showed that the NetDDE
> vulnerability can not be exploited with a NULL session a.k.a
> with "Anonymous Logon" credentials.

Can you share the function name/location, perchance? :) I'm curious what
the bug looks like.
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://www.immunitysec.com/mailman/listinfo/dailydave