Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Is Windows TCP/IP source routing PoC code available?

Re: Is Windows TCP/IP source routing PoC code available?

From: 3APA3A <3APA3A_at_SECURITY.NNOV.RU>
Date: Tue, 27 Jun 2006 13:28:03 +0400

Dear Denis Jedig,

Simple PoC and original message from Andrey Minaev, dated February, 2006
in Russian with short translation to English) are available from

http://www.security.nnov.ru/Fnews753.html

This is his original post regarding this issue as it was in his first
report to MS and it may not contain complete information because I am
not aware about results of further researches with Microsoft.

I don't know why Andrey have not published complete information yet. I
had no contacts with him after MS opened case on this issue and he asked
to hold information.

--Sunday, June 25, 2006, 10:03:24 PM, you wrote to vuln-dev_at_securityfocus.com:

DJ> Greetings to the list,

DJ> As known, Microsoft did announce a security vulnerability concerning an
DJ> overflow within the TCP/IP stack implementation when source routing
DJ> fields are used:
DJ> http://www.microsoft.com/technet/security/bulletin/MS06-032.mspx

DJ> Is anyone aware of an exploit or POC code for this vulnerability? The
DJ> security bulletin states that Windows XP SP2 and Windows Server 2003 SP1
DJ> are "secure by default" due to disabled source routing. However, it does
DJ> not provide sufficient information regarding other operating systems
DJ> affected, so I would like to check out by myself.

DJ> Regards,

DJ> Denis Jedig
DJ> syneticon networks GbR

-- 
~/ZARAZA
...без дубинки никогда не принимался он за программирование. (Лем)
Received on Jun 27 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos