OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RPC DCOM exploit

From: Peter Fry (pafhaxed.net)
Date: Thu Jul 31 2003 - 12:54:53 CDT


We had what looks like an exploit for this vulnerability go around our
office network and only one machine was (seriously) affected. Somone
managed to get the machine to start spamming random IPs with what looked
like the exploit, sending out about 700 RPC pings per second. About the
same time, we had a NET SEND
message pop up on our windows boxen advertizing www.freeautobot.com.
Could this be a new tactic to propigate their spamulous message prompts?

Peter

---------------------------------------------------------------------------
----------------------------------------------------------------------------