Security Incidents mailing list archives

Re: Dameware scans, worm?


From: "Steven M. Christey" <coley () mitre org>
Date: Fri, 23 Jan 2004 19:50:02 -0500 (EST)


Regarding the varying source ports for the Dameware scans:

Based on an *incomplete* and *quick* glance through two recently
posted exploits for a Dameware vulnerability (CVE CAN-2003-1030):

  1) both exploits use a reverse shell

  2) both exploits take the "source port" on the command line

So, the attacker can control which port is used.

The exploits that I glanced at are:

  Bugtraq, January 10, 2004
  DameWare Mini Remote Control < v3.73 remote exploit by kralor]
  http://marc.theaimsgroup.com/?l=bugtraq&m=107392603615840&w=2

  Bugtraq, December 19, 2003
  [Exploit]: DameWare Mini Remote Control Server Overflow Exploit
  http://marc.theaimsgroup.com/?l=bugtraq&m=107187110617266&w=2


- Steve

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: