Dailydave mailing list archives

Re: Immunity PoC for MSDTC?


From: Dave Aitel <dave () immunitysec com>
Date: Sun, 27 Nov 2005 18:31:31 -0500

If my quick read is correct, this is a different issue from the one we exploited. One patch, many bugs. I think we thought the other vulnerability was more exploitable than this one, even if it has reliability issues.

-dave

Andrew Simmons wrote:
http://www.securityfocus.com/bid/15056/exploit :

"Microsoft Windows MSDTC Memory Corruption Vulnerability

"Reports indicate that Immunity has developed a proof of concept exploit for this issue."

[...]

/*
\ MSDTC remote PoC exploit
/ by Darkeagle
\
/
\ Unl0ck Research Team
/
\
/ Greetingz: all UKT boys, 0x557 guys, Sowhat, GHC/RST guys
\
/ Exploit tested on: Windows 2000 Professional Russian Service Pack 4
\


Hmmmm!


\a



Current thread: