OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Dailydave] SMBv2

From: dave (daveimmunityinc.com)
Date: Mon Sep 14 2009 - 14:18:52 CDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

An SMBv2 Vista exploit is out: http://www.immunityinc.com/ceu-index.shtml

Currently it's a local. Kostya's technique on this is, in my personal
opinion, going to become a remote shortly. It's different from Lurene's
technique as posted to the VRT page. I guess there's more than one way
to skin a cat?

For the inevitable questions: We won't be commenting publicly on the
exploit specifics, but you could always purchase a CEU subscription and
find them out. Nicolas Pouvesle, Kostya, and Skylar have a mandate to
"crack it like a nut" which I'm sure they will proceed to do. :>

- -dave
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkqulxwACgkQtehAhL0gheo0rwCfadjLfsCKhQPppWe97sL76//a
PAoAn3PXEhvreK8jf1GcN5yJ5GU+QWMd
=cMjg
-----END PGP SIGNATURE-----
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave