OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] Securify bulletin: Microsoft Active Directory Denial-of-service

From: Michael Wojcik (Michael.Wojcikmicrofocus.com)
Date: Fri Jun 13 2008 - 13:31:30 CDT


> From: Securify Bulletins [mailto:bulletinsSecurify.com]
> Sent: Friday, 13 June, 2008 12:44
> To: bugtraqsecurityfocus.com; full-disclosurelists.grok.org.uk
>
> IV. WORKAROUNDS:
>
> Block TCP ports 389 and 3268 to your Active Directory
> server from untrusted sources.

AD may also be listening on 636 for LDAP-over-SSL.

--
Michael Wojcik
Principal Software Systems Developer, Micro Focus

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/