|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Dailydave] Useless fact of the day!
From: Rhys Kidd (rhyskidd
gmail.com)
Date: Sat Jan 06 2007 - 07:39:50 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
RPC memory exhaustion bugs are all the rage atm it would seem,
hopefully this will provide the traction for MSRC to give it
priority....
It's also interesting that ISC believe for servers that the current
UPnP and SPOOLSS bugs are 'Important', whereas the more recent
NetrWkstaUserEnum() bug is only 'Less Urgent'.
They are pretty much the same, due to unvalidated client input, and in
fact the NetrWkstaUserEnum() opnum ( through the wkssvc named pipe )
is usually bindable over an anonymous NULL session.
- Rhys
_______________________________________________
Dailydave mailing list
Dailydave
lists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]